Flowise是FlowiseAI开源的一个用于轻松构建 LLM 应用程序的工具。 Flowise 3.1.2之前版本存在访问控制错误漏洞,该漏洞源于聊天流更新端点缺少服务器端验证和授权检查,可能导致批量赋值漏洞,允许经过身份验证的用户操纵聊天流的内部属性并将其重新分配到另一个工作区,导致跨工作区资源重新分配以及部署和可见性设置的未授权修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42862 | Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignm | |
| CVE-2026-42861 | Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reass | |
| CVE-2026-46476 | Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template take | |
| CVE-2026-46479 | Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeov | |
| CVE-2026-46475 | Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover | |
| CVE-2026-46444 | Flowise: Vector Store No Permission Checks | |
| CVE-2026-46478 | Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover | |
| CVE-2026-46442 | Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox E | |
| CVE-2026-46477 | Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover | |
| CVE-2026-46480 | Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover | |
| CVE-2026-46440 | Flowise: Basic Auth Credentials Exposed via API | |
| CVE-2026-46443 | Flowise: Credential Data Leak | |
| CVE-2026-46441 | Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reas |
No comments yet