Flowise是FlowiseAI开源的一个用于轻松构建 LLM 应用程序的工具。 Flowise 3.0.5版本存在代码注入漏洞,该漏洞源于CustomMCP节点直接执行用户输入的JavaScript代码,可能导致远程代码执行。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/zimshk/CVE-2025-59528.yaml | POC详情 |
| 2 | CVE-2025-59528 | https://github.com/B1ack4sh/Blackash-CVE-2025-59528 | POC详情 |
| 3 | CVE-2025-59528 | https://github.com/Ashwesker/Blackash-CVE-2025-59528 | POC详情 |
| 4 | CVE-2025-59528 | https://github.com/Ashwesker/Ashwesker-CVE-2025-59528 | POC详情 |
| 5 | Flowise 3.0.5 contains a remote code execution vulnerability caused by unsafe evaluation of user input in the CustomMCP node's convertToValidJSONString function, letting remote attackers execute arbitrary code with full Node.js privileges, exploit requires user input to be processed by the vulnerable node. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-59528.yaml | POC详情 |
| CVE-2025-59434 | 9.6 CRITICAL | Flowise 访问控制错误漏洞 |
| CVE-2025-59527 | 7.5 HIGH | Flowise 代码问题漏洞 |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.