FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise 3.1.2之前版本存在输入验证错误漏洞,该漏洞源于PUT /api/v1/user端点存在批量赋值问题,允许经过身份验证的用户在未经验证的情况下直接修改凭据字段,攻击者可通过提供特制的密码哈希绕过密码更改验证和会话失效,从而实现临时会话泄露后的持久账户访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58351 | 9.8 CRITICAL | Flowise - Remote Code Execution via overrideConfig Parameter |
| CVE-2025-71331 | 6.1 MEDIUM | Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows |
| CVE-2026-56267 | Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint |
No comments yet