FlowiseAI Flowise是FlowiseAI公司开源的一款可视化编排语言模型应用流程的工具。 FlowiseAI Flowise 3.1.3之前版本存在代码注入漏洞,该漏洞源于Custom MCP节点在CUSTOM_MCP_PROTOCOL设置为stdio时存在远程代码执行漏洞,攻击者可通过操纵环境变量和命令参数绕过验证,可能导致已认证用户执行任意命令或系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73483 | 9.4 CRITICAL | Flowise before 3.1.3 Sandbox Escape via Puppeteer |
| CVE-2026-73487 | 9.0 CRITICAL | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
| CVE-2026-73485 | 9.0 CRITICAL | Flowise before 3.1.3 Remote Code Execution via Airtable Agent |
| CVE-2026-73486 | 9.0 CRITICAL | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
| CVE-2026-73602 | 9.0 CRITICAL | Flowise before 3.1.3 Sandbox Escape to RCE |
| CVE-2026-73484 | 8.6 HIGH | Flowise before 3.1.3 Sandbox Escape via Pandas Methods |
| CVE-2026-73604 | 6.5 MEDIUM | Flowise before 3.1.3 Credential Exposure via API |
| CVE-2026-73603 | 6.3 MEDIUM | Flowise before 3.1.4 Credential Abuse via Text-to-Speech |
| CVE-2026-73488 | 6.0 MEDIUM | Flowise before 3.1.3 IDOR via customer-default-source endpoint |
No comments yet