Flowise 在 3.1.4 之前的版本未能对聊天模型节点中的 参数进行有效验证,导致经过身份验证的用户可以将请求重定向到任意主机。拥有 或 权限的攻击者可以通过将请求重定向到云元数据服务或内部主机,窃取大型语言模型(LLM)提供商的 API 密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91934 | 8.8 HIGH | Flowise before 3.1.4 Remote Code Execution via SQL Database Chain |
| CVE-2026-91931 | 8.5 HIGH | Flowise before 3.1.4 Remote Code Execution via Custom MCP npx |
| CVE-2026-91932 | 8.5 HIGH | Flowise before 3.1.4 Remote Code Execution via cwd Parameter |
| CVE-2026-91930 | 7.5 HIGH | Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover |
| CVE-2026-91937 | 7.5 HIGH | Flowise before 3.1.4 NoSQL Injection via sessionId |
| CVE-2026-91933 | 7.1 HIGH | Flowise before 3.1.4 Authorization Bypass via openai-realtime |
| CVE-2026-91929 | 7.1 HIGH | Flowise before 3.1.4 Cross-Tenant Authorization Bypass |
| CVE-2026-91938 | 7.1 HIGH | Flowise before 3.1.4 Server-Side Request Forgery via document loaders |
| CVE-2026-91936 | 6.8 MEDIUM | Flowise before 3.1.4 Script Injection via Docker Workflows |
No comments yet