Flowise 3.1.4 版本之前的版本中存在一个未经身份验证的服务拒绝(DoS)漏洞,位于 端点。该端点在接收用户提供的 和 时未进行所有权验证。攻击者可以通过提交包含已知 chatflow 和 chat 标识符的请求,终止任何用户的活跃 chatflow 预测,从而造成针对性的服务中断。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90534 | 6.1 MEDIUM | Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method |
| CVE-2026-90533 | 6.0 MEDIUM | Flowise before 3.1.4 Broken Access Control via organizationuser |
No comments yet