Flowise 3.1.4 版本(启用 SSO 的企业版/平台模式)在 SSO 登录路径中存在身份验证绕过漏洞。当收到一个 SSO 回调请求,其携带的电子邮件地址匹配状态为“已邀请”(INVITED)的用户时, 函数(位于 SSOBase.ts 第 80–94 行)会从数据库中复制该用户记录——包括服务器端存储的单次使用邀请临时令牌(tempToken)——并将这些数据传递给 。由于注册处理程序中的令牌查找、邮箱匹配和过期检查均基于服务器自身存储的令牌而非调用方提供的令牌,因此这些检查被轻易绕过,从而使该用户账户及
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100608 | 8.3 HIGH | Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard |
| CVE-2026-100607 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via Email-Only SSO |
| CVE-2026-100610 | 7.5 HIGH | Flowise through 3.1.4 Missing Authorization via upsert-history |
| CVE-2026-100605 | 7.1 HIGH | Flowise through 3.1.4 Missing Authorization via Chat Message Routes |
| CVE-2026-100609 | 6.8 MEDIUM | Flowise through 3.1.4 Insecure Direct Object Reference via Credential |
No comments yet