在 Flowring Agentflow 4.0 版本(2023年3月24日之前)的 API 接口中存在“路径限制不当(路径遍历)”漏洞。该漏洞允许经过身份验证的远程攻击者通过 参数,将文件写入到预期上传目录之外的任意位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Flowring Technology Corp | Agentflow 4.0 | 0 ~ 2023/03/24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96428 | 9.3 CRITICAL | Flowring Agentflow 4.0 - SQL Injection |
| CVE-2026-96431 | 9.3 CRITICAL | Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type |
| CVE-2026-96429 | 9.3 CRITICAL | Flowring Agentflow 4.0 - SQL Injection |
| CVE-2026-96430 | 8.7 HIGH | Flowring Agentflow 4.0 - Exposed Dangerous Method or Function |
No comments yet