Flowise 3.1.4 之前的版本在 接口中存在访问控制失效漏洞。该漏洞允许任何已认证的组织成员通过传入任意用户 ID 查询该接口,从而获取组织所有者的完整用户记录,包括其 bcrypt 密码哈希值以及临时令牌。攻击者可以提取所有者的高特权账户凭据哈希值,并对其进行离线破解,最终实现对该最高权限账户的接管(账号劫持)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90535 | 6.3 MEDIUM | Flowise before 3.1.4 Denial of Service via text-to-speech/abort |
| CVE-2026-90534 | 6.1 MEDIUM | Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method |
No comments yet