Flowise 3.1.4 版本在 BullMQ 管理仪表板方面未实施正确的授权控制。当服务器以队列模式运行且启用了仪表板(即满足 MODE=queue、ENABLE_BULLMQ_DASHBOARD=true,且非云端模式 isCloud() 为 false)时,/admin/queues 挂载点仅由 verifyTokenForBullMQDashboard 中间件进行保护。该中间件仅验证 JWT 令牌的有效性,但并未执行任何角色、权限或工作区/组织范围的授权检查。此外,该挂载点位于 /api/v1/* 范围之
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100607 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via Email-Only SSO |
| CVE-2026-100606 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via SSO Email Match |
| CVE-2026-100610 | 7.5 HIGH | Flowise through 3.1.4 Missing Authorization via upsert-history |
| CVE-2026-100605 | 7.1 HIGH | Flowise through 3.1.4 Missing Authorization via Chat Message Routes |
| CVE-2026-100609 | 6.8 MEDIUM | Flowise through 3.1.4 Insecure Direct Object Reference via Credential |
No comments yet