受影响的 Flowintel 版本允许攻击者控制的笔记内容在 PDF 导出过程中通过 Pandoc 和 XeLaTeX 进行处理,从而可能导致读取并包含 Flowintel 服务器上的本地文件到生成的导出文档中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81826 | 9.1 CRITICAL | Flowintel Fails to Invalidate Active Sessions After Password Change |
| CVE-2026-81662 | 8.6 HIGH | Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configur |
| CVE-2026-81818 | 8.6 HIGH | Flowintel Organization Administrator Can Reset Full Administrator Password and Escalate Pr |
| CVE-2026-81743 | 7.5 HIGH | Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template Injection |
| CVE-2026-81817 | 7.2 HIGH | Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification |
| CVE-2026-81827 | 6.9 MEDIUM | Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Email Input |
| CVE-2026-81819 | 5.3 MEDIUM | Flowintel Missing Authorization Allows Regular API Users to View Other Users’ Task Assignm |
| CVE-2026-81814 | 5.1 MEDIUM | Flowintel Stored XSS in Calendar via Malicious Case Title |
| CVE-2026-81753 | 5.1 MEDIUM | Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content |
| CVE-2026-81820 | 5.1 MEDIUM | Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Attributes |
No comments yet