7.1

CVSS3.1

CVE-2026-41270 - Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection via HTTP_DENY_LIST for axios and node…

📅 Published: April 23, 2026, 7:15 p.m. 🔄 Last Modified: April 24, 2026, 4:38 p.m.

7.1

CVSS3.1

CVE-2026-41269 - Flowise: File Upload Validation Bypass in createAttachment

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally al…

📅 Published: April 23, 2026, 7:14 p.m. 🔄 Last Modified: April 24, 2026, 4:39 p.m.

9.8

CVSS3.1

CVE-2026-41268 - Flowise: Flowise Parameter Override Bypass Remote Command Execution

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the FILE-STORAGE:: keyword combined wi…

📅 Published: April 23, 2026, 7:13 p.m. 🔄 Last Modified: April 24, 2026, 3:14 p.m.

8.1

CVSS3.1

CVE-2026-41267 - Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Associa…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objec…

📅 Published: April 23, 2026, 7:12 p.m. 🔄 Last Modified: April 24, 2026, 3:14 p.m.

7.7

CVSS4.0

CVE-2026-41266 - Flowise: Sensitive Data Leak in public-chatbotConfig

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just o…

📅 Published: April 23, 2026, 7:11 p.m. 🔄 Last Modified: April 25, 2026, 1:27 a.m.

9.4

CVSS4.0

CVE-2026-41137 - Flowise: Code Injection in CSVAgent leads to Authenticated RCE

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the serve…

📅 Published: April 23, 2026, 7:10 p.m. 🔄 Last Modified: April 24, 2026, 3:15 p.m.

8.8

CVSS3.1

CVE-2026-41138 - Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verificati…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within t…

📅 Published: April 23, 2026, 7:05 p.m. 🔄 Last Modified: April 24, 2026, 6:20 p.m.

8.2

CVSS4.0

CVE-2026-41259 - Mastodon: Insufficient verification of email addresses

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted diff…

📅 Published: April 23, 2026, 6:55 p.m. 🔄 Last Modified: April 23, 2026, 7:24 p.m.

7.7

CVSS4.0

CVE-2026-41205 - Mako: Path traversal via double-slash URI prefix in TemplateLookup

Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can …

📅 Published: April 23, 2026, 6:52 p.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.

8.9

CVSS4.0

CVE-2026-41247 - elFinder: Command injection in resize background color parameter when using ImageMagick CLI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In c…

📅 Published: April 23, 2026, 6:47 p.m. 🔄 Last Modified: April 25, 2026, 1:25 a.m.
Total resulsts: 346572
Page 41 of 34,658
« previous page » next page
Filters