Flowise 3.1.4 版本中存在缺失的路由级基于角色的访问控制(RBAC)检查,位于聊天消息端点。该漏洞允许低权限的 API 密钥读取和删除聊天历史记录。拥有合法但权限较低的 API 密钥的攻击者可以绕过必需的流程权限,访问用于获取聊天历史、提示(prompts)、模型响应以及删除消息的 GET 和 DELETE 路由。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100608 | 8.3 HIGH | Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard |
| CVE-2026-100607 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via Email-Only SSO |
| CVE-2026-100606 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via SSO Email Match |
| CVE-2026-100610 | 7.5 HIGH | Flowise through 3.1.4 Missing Authorization via upsert-history |
| CVE-2026-100609 | 6.8 MEDIUM | Flowise through 3.1.4 Insecure Direct Object Reference via Credential |
No comments yet