Flowise 在 3.1.4 版本之前存在服务器端请求伪造(SSRF)漏洞,该漏洞位于 Cheerio、Playwright 和 Puppeteer 文档加载器节点中,并且可以绕过 SSRF 防护机制。攻击者可以提供任意 URL 来获取云元数据、内部服务和私有网络资源,且响应内容会作为文档文本返回。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91934 | 8.8 HIGH | Flowise before 3.1.4 Remote Code Execution via SQL Database Chain |
| CVE-2026-91931 | 8.5 HIGH | Flowise before 3.1.4 Remote Code Execution via Custom MCP npx |
| CVE-2026-91932 | 8.5 HIGH | Flowise before 3.1.4 Remote Code Execution via cwd Parameter |
| CVE-2026-91935 | 8.3 HIGH | Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes |
| CVE-2026-91930 | 7.5 HIGH | Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover |
| CVE-2026-91937 | 7.5 HIGH | Flowise before 3.1.4 NoSQL Injection via sessionId |
| CVE-2026-91933 | 7.1 HIGH | Flowise before 3.1.4 Authorization Bypass via openai-realtime |
| CVE-2026-91929 | 7.1 HIGH | Flowise before 3.1.4 Cross-Tenant Authorization Bypass |
| CVE-2026-91936 | 6.8 MEDIUM | Flowise before 3.1.4 Script Injection via Docker Workflows |
No comments yet