8.7

CVSS4.0

CVE-2026-6375 - Authorization bypass through User-Controlled key in SpiceJet Online Booking System

A vulnerability in SpiceJetโ€™s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw โ€ฆ

๐Ÿ“… Published: April 23, 2026, 8:07 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:19 p.m.

9.2

CVSS4.0

CVE-2026-41264 - Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can leverโ€ฆ

๐Ÿ“… Published: April 23, 2026, 8 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 3:15 p.m.

9.2

CVSS4.0

CVE-2026-41265 - Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:58 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 3:15 p.m.

8.2

CVSS4.0

CVE-2026-41279 - Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs โ€” enables API credit abuse vโ€ฆ

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (no auth) and accepts a credentialId directly in the request body. When called without a chatflowId, โ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:53 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:31 p.m.

8.7

CVSS4.0

CVE-2026-41278 - Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwoโ€ฆ

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker validation revealed this is worse than initially assessed: the saโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:31 p.m.

7.7

CVSS4.0

CVE-2026-41276 - Flowise: AccountService resetPassword Authentication Bypass Vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific flaโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:49 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

7.6

CVSS4.0

CVE-2026-41277 - Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover โ€ฆ

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. Because theโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:48 p.m. ๐Ÿ”„ Last Modified: April 25, 2026, 1:31 a.m.

9.3

CVSS4.0

CVE-2026-25874 - LeRobot Unsafe Deserialization Remote Code Execution via gRPC

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attaโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:45 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:20 p.m.

7.5

CVSS4.0

CVE-2026-41275 - Flowise: Password Reset Link Sent Over Unsecured HTTP

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behavior introduces the risk of a man-in-the-middle (Mโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:33 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:34 p.m.

7.7

CVSS4.0

CVE-2026-41273 - Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatfloโ€ฆ

๐Ÿ“… Published: April 23, 2026, 7:29 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.
Total resulsts: 346614
Page 44 of 34,662
ยซ previous page ยป next page
Filters