FlowiseAI Flowise是FlowiseAI公司开源的一款可视化编排语言模型应用流程的工具。 FlowiseAI Flowise 3.1.4之前版本存在授权问题漏洞,该漏洞源于未验证chatflow可见性,可能导致未经身份验证的攻击者滥用私有chatflow TTS凭据,利用存储的OpenAI或ElevenLabs API密钥生成无限文本转语音音频,造成账户费用损失。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73483 | 9.4 CRITICAL | Flowise before 3.1.3 Sandbox Escape via Puppeteer |
| CVE-2026-73487 | 9.0 CRITICAL | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
| CVE-2026-73485 | 9.0 CRITICAL | Flowise before 3.1.3 Remote Code Execution via Airtable Agent |
| CVE-2026-73601 | 9.0 CRITICAL | Flowise before 3.1.3 Remote Code Execution via Custom MCP |
| CVE-2026-73486 | 9.0 CRITICAL | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
| CVE-2026-73602 | 9.0 CRITICAL | Flowise before 3.1.3 Sandbox Escape to RCE |
| CVE-2026-73484 | 8.6 HIGH | Flowise before 3.1.3 Sandbox Escape via Pandas Methods |
| CVE-2026-73604 | 6.5 MEDIUM | Flowise before 3.1.3 Credential Exposure via API |
| CVE-2026-73488 | 6.0 MEDIUM | Flowise before 3.1.3 IDOR via customer-default-source endpoint |
No comments yet