FlowiseAI Flowise是FlowiseAI公司开源的一款可视化编排语言模型应用流程的工具。 FlowiseAI Flowise 3.1.3之前版本存在代码注入漏洞,该漏洞源于Airtable Agent节点存在代码注入漏洞,通过混淆技术绕过pythonCodeValidator黑名单,可能导致未经身份验证的攻击者向使用该节点的chatflow发送特制提示,注入恶意Python代码并在无沙箱的pyodide环境中执行,从而完全访问主机操作系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73483 | 9.4 CRITICAL | Flowise before 3.1.3 Sandbox Escape via Puppeteer |
| CVE-2026-73487 | 9.0 CRITICAL | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
| CVE-2026-73601 | 9.0 CRITICAL | Flowise before 3.1.3 Remote Code Execution via Custom MCP |
| CVE-2026-73486 | 9.0 CRITICAL | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
| CVE-2026-73602 | 9.0 CRITICAL | Flowise before 3.1.3 Sandbox Escape to RCE |
| CVE-2026-73484 | 8.6 HIGH | Flowise before 3.1.3 Sandbox Escape via Pandas Methods |
| CVE-2026-73604 | 6.5 MEDIUM | Flowise before 3.1.3 Credential Exposure via API |
| CVE-2026-73603 | 6.3 MEDIUM | Flowise before 3.1.4 Credential Abuse via Text-to-Speech |
| CVE-2026-73488 | 6.0 MEDIUM | Flowise before 3.1.3 IDOR via customer-default-source endpoint |
No comments yet