FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise 3.0.1版本存在授权问题漏洞,该漏洞源于/api/v1/account/register端点未受保护,可能导致未经验证的攻击者创建用户账户,进而注册任意账户并认证系统,获得完整API访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-71338 | 10.0 CRITICAL | Flowise - Arbitrary File Write to Remote Code Execution via document-store API |
| CVE-2025-71336 | 9.8 CRITICAL | Flowise - Unsandboxed Remote Code Execution via Custom MCP |
| CVE-2025-71334 | 9.8 CRITICAL | Flowise - Arbitrary File Access via Missing Chat Flow ID Validation |
| CVE-2025-71328 | 8.3 HIGH | Flowise - Unverified Password Change via Account Settings |
| CVE-2025-71335 | 8.1 HIGH | Flowise - Session Invalidation Failure After Password Change |
| CVE-2025-71324 | 7.5 HIGH | Flowise - Arbitrary File Read via chatId Parameter |
| CVE-2025-71333 | Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint |
No comments yet