FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 Flowise 3.0.13之前版本存在加密问题漏洞,该漏洞源于使用bcrypt时设置默认盐轮数为5,仅提供32次迭代而非OWASP推荐的至少10轮,导致攻击者使用现代GPU硬件破解密码哈希的速度提高约30倍,可能在数据库泄露事件中危及所有用户账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56270 | 7.5 HIGH | Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint |
| CVE-2025-71332 | 6.5 MEDIUM | Flowise - SQL Injection in importChatflows API via chatflow.id Parameter |
| CVE-2026-56269 | 4.6 MEDIUM | Flowise - Weak Default Token Hash Secret in JWT Token Encryption |
No comments yet