FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise 3.0.8之前版本存在跨站脚本漏洞,该漏洞源于对聊天消息和自定义代理函数中的输入过滤不足,可能导致攻击者通过发送iframe有效载荷或让自定义代理函数从外部网站返回XSS有效载荷来注入恶意JavaScript脚本,从而窃取Cookie和会话数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58351 | 9.8 CRITICAL | Flowise - Remote Code Execution via overrideConfig Parameter |
| CVE-2026-56276 | Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override | |
| CVE-2026-56267 | Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint |
No comments yet