Flowise(npm 包 和 )在 3.1.4 版本中存在一个权限绕过漏洞。在多个代码路径中,系统通过 ID 查找凭据时,未对请求用户所属的工作区(workspace)进行过滤(即使用 查询,但未附加 条件)。受影响的代码路径包括: / (对应接口: 和 ) (对应接口: ) (对应接口: ;该接口可通过先通过 导入一个恶意构造的 assistant 记录来触发) 被 使用的共享辅助函数(对应接口: ) 由于上述缺陷,一个已认证的用户(属于某一工作区)可以提供一个属于其他工作区的凭据 UUID,从而导致服务器在攻
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100608 | 8.3 HIGH | Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard |
| CVE-2026-100607 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via Email-Only SSO |
| CVE-2026-100606 | 7.7 HIGH | Flowise through 3.1.4 Authentication Bypass via SSO Email Match |
| CVE-2026-100610 | 7.5 HIGH | Flowise through 3.1.4 Missing Authorization via upsert-history |
| CVE-2026-100605 | 7.1 HIGH | Flowise through 3.1.4 Missing Authorization via Chat Message Routes |
No comments yet