Flowise 3.1.4 及之前版本仅通过电子邮件来识别单点登录(SSO)和本地密码用户,而未存储身份提供商(provider)或主题标识符(subject identifier)的绑定信息。这使得攻击者可以通过在任何已配置的 SSO 提供商处声称受害者的电子邮件,从而伪装成任何现有用户进行身份验证。攻击者可以通过通过不同的 SSO 提供商或本地密码(而非受害者最初注册时使用的方法)进行身份验证,从而获得对账户的完全访问权限,包括聊天流程(chatflows)、凭证(credentials)和 API 密钥等敏感
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100608 | 8.3 HIGH | Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard |
| CVE-2026-100606 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via SSO Email Match |
| CVE-2026-100610 | 7.5 HIGH | Flowise through 3.1.4 Missing Authorization via upsert-history |
| CVE-2026-100605 | 7.1 HIGH | Flowise through 3.1.4 Missing Authorization via Chat Message Routes |
| CVE-2026-100609 | 6.8 MEDIUM | Flowise through 3.1.4 Insecure Direct Object Reference via Credential |
No comments yet