FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise 3.1.0之前版本和3.0.13及之前版本存在信任管理问题漏洞,该漏洞源于使用弱硬编码默认值“Secre$t”作为TOKEN_HASH_SECRET环境变量,可能导致获取内部标识符和操作元数据,有助于权限提升或未授权数据访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56270 | 7.5 HIGH | Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint |
| CVE-2025-71332 | 6.5 MEDIUM | Flowise - SQL Injection in importChatflows API via chatflow.id Parameter |
| CVE-2026-56272 | 4.1 MEDIUM | Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing |
No comments yet