受影响的 Flowintel 版本允许通过系统设置修改 配置值,且未将其限制在预期的日志目录内的文件名范围内。 由于应用程序根据该可配置值构建日志写入路径,管理员可以将 设置为任意文件系统路径。攻击者能够影响被记录的内容,从而能够将受控数据写入到非预期的文件中。上游提交特别描述了一条利用链:攻击者先将模板注入到选定的文件中,随后利用应用程序的渲染行为来执行代码。 该补丁做了以下改动: 从可通过网页编辑的设置中移除了 ; 引入了 函数,用于拒绝绝对路径、路径遍历(如 )、Windows 风格路径、空字节以及包含目录成
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81826 | 9.1 CRITICAL | Flowintel Fails to Invalidate Active Sessions After Password Change |
| CVE-2026-81662 | 8.6 HIGH | Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configur |
| CVE-2026-81818 | 8.6 HIGH | Flowintel Organization Administrator Can Reset Full Administrator Password and Escalate Pr |
| CVE-2026-81817 | 7.2 HIGH | Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification |
| CVE-2026-81659 | 7.1 HIGH | Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing |
| CVE-2026-81827 | 6.9 MEDIUM | Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Email Input |
| CVE-2026-81819 | 5.3 MEDIUM | Flowintel Missing Authorization Allows Regular API Users to View Other Users’ Task Assignm |
| CVE-2026-81814 | 5.1 MEDIUM | Flowintel Stored XSS in Calendar via Malicious Case Title |
| CVE-2026-81753 | 5.1 MEDIUM | Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content |
| CVE-2026-81820 | 5.1 MEDIUM | Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Attributes |
No comments yet