FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise 存在输入验证错误漏洞,该漏洞源于对/api/v1/document-store/loader/process端点中的fileName参数清理不当,可能导致未经身份验证的攻击者利用../序列写入任意文件,覆盖关键文件如package.json,并在应用重启时实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-71336 | 9.8 CRITICAL | Flowise - Unsandboxed Remote Code Execution via Custom MCP |
| CVE-2025-71334 | 9.8 CRITICAL | Flowise - Arbitrary File Access via Missing Chat Flow ID Validation |
| CVE-2025-71327 | 9.1 CRITICAL | Flowise - Authentication Bypass via Unprotected Registration Endpoint |
| CVE-2025-71328 | 8.3 HIGH | Flowise - Unverified Password Change via Account Settings |
| CVE-2025-71335 | 8.1 HIGH | Flowise - Session Invalidation Failure After Password Change |
| CVE-2025-71324 | 7.5 HIGH | Flowise - Arbitrary File Read via chatId Parameter |
| CVE-2025-71333 | Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint |
No comments yet