FlowiseAI Flowise是FlowiseAI公司开源的一款可视化编排语言模型应用流程的工具。 FlowiseAI Flowise 3.1.3之前版本存在输入验证错误漏洞,该漏洞源于pythonCodeValidator.ts未能阻止Pandas DataFrame原生方法(如to_csv、to_json、pipe和query),可能导致经过身份验证的攻击者窃取上传的CSV数据或向服务器文件系统写入任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73483 | 9.4 CRITICAL | Flowise before 3.1.3 Sandbox Escape via Puppeteer |
| CVE-2026-73487 | 9.0 CRITICAL | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
| CVE-2026-73485 | 9.0 CRITICAL | Flowise before 3.1.3 Remote Code Execution via Airtable Agent |
| CVE-2026-73601 | 9.0 CRITICAL | Flowise before 3.1.3 Remote Code Execution via Custom MCP |
| CVE-2026-73486 | 9.0 CRITICAL | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
| CVE-2026-73602 | 9.0 CRITICAL | Flowise before 3.1.3 Sandbox Escape to RCE |
| CVE-2026-73604 | 6.5 MEDIUM | Flowise before 3.1.3 Credential Exposure via API |
| CVE-2026-73603 | 6.3 MEDIUM | Flowise before 3.1.4 Credential Abuse via Text-to-Speech |
| CVE-2026-73488 | 6.0 MEDIUM | Flowise before 3.1.3 IDOR via customer-default-source endpoint |
No comments yet