References https://www.secrss.com/articles/83128 https://www.secevery.com/toBugInfo?id=1967783575010680834 https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-99pg-hqvx-r4gf https://cn-sec.com/archives/4476916.html https://adg.csdn.net/696f4e41437a6b403369f8fd.html https://www.xtcaq.com/nd.jsp?id=9830 https://blog.csdn.net/destiny_one/article/details/152800580 https://cn-sec.com/archives/4532500.html
Related VulnerabilitiesPoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API ExposureFlowise /api/v1/loginmethod 未授权访问漏洞(CVE-2026-56270)PoCCVE-2026-56270: Flowise <= 3.0.13 - Unauthenticated OAuth Configuration DisclosurePoCCVE-2025-71324: Flowise - Path TraversalPoCCVE-2026-69251: Flowise < 3.1.3 - Remote Code ExecutionFlowise /api/v1/chatflows 文件上传漏洞(CVE-2025-71334)PoCCVE-2025-71334: Flowise - Path TraversalPoCCVE-2026-46442: Flowise < 3.1.2 - node-custom-function Unauthorized RCEFlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442)PoCCVE-2024-36420: Flowise 1.4.3 - Arbitrary File Read金叶物联网大数据管理平台 /data/file/download 文件读取漏洞Flowise 任意文件读取漏洞(CVE-2024-36420)PoCCVE-2026-30824: Flowise - NVIDIA NIM Endpoints Missing Authentication