๐จ CVE-2026-91929
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
๐@cveNotify
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
๐@cveNotify
GitHub
Cross-tenant/cross-org authorization gaps in Enterprise role, and SSO-config endpoints
### Summary
Five Enterprise-tier endpoints fetch or mutate a workspace/organization/role by a client-supplied id with no verification that it belongs to the acting user's own org/workspace. Al...
Five Enterprise-tier endpoints fetch or mutate a workspace/organization/role by a client-supplied id with no verification that it belongs to the acting user's own org/workspace. Al...
๐จ CVE-2026-91930
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
๐@cveNotify
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
๐@cveNotify
GitHub
Cross-tenant organization admin takeover via unscoped organization/workspace membership APIs
# Cross-tenant organization admin takeover via unscoped organization/workspace membership APIs
I am privately reporting a novel cross-tenant authorization bypass in Flowise Enterprise/Cloud mult...
I am privately reporting a novel cross-tenant authorization bypass in Flowise Enterprise/Cloud mult...
๐จ CVE-2026-91931
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
๐@cveNotify
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
๐@cveNotify
GitHub
Flowise Custom MCP npx package execution leads to authenticated server-side command execution
# Flowise Authenticated Command Execution via Custom MCP `npx`
## Summary
Flowise is an open-source visual platform for building LLM applications, chatflows, agents, and tool integrations. Fl...
## Summary
Flowise is an open-source visual platform for building LLM applications, chatflows, agents, and tool integrations. Fl...
๐จ CVE-2026-91932
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
๐@cveNotify
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
๐@cveNotify
GitHub
Flowise MCP Server Config cwd Parameter Validation Bypass
### Summary
A validation bypass in Flowise's MCP server configuration allows authenticated attackers to achieve arbitrary code execution by exploiting an unvalidated `cwd` parameter that bypas...
A validation bypass in Flowise's MCP server configuration allows authenticated attackers to achieve arbitrary code execution by exploiting an unvalidated `cwd` parameter that bypas...
๐จ CVE-2026-91933
Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.
๐@cveNotify
Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.
๐@cveNotify
GitHub
openai-realtime endpoints allow cross-workspace tool disclosure and execution via unscoped chatflow ID
### Summary
`GET /api/v1/openai-realtime/:id` and `POST /api/v1/openai-realtime/:id` in Flowise allow a user or API key from one workspace to disclose and execute tools belonging to a `ChatFlow`...
`GET /api/v1/openai-realtime/:id` and `POST /api/v1/openai-realtime/:id` in Flowise allow a user or API key from one workspace to disclose and execute tools belonging to a `ChatFlow`...
๐จ CVE-2026-91934
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.
๐@cveNotify
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.
๐@cveNotify
GitHub
Flowise RCE via SQL Database Chain Node
=============================================================================
Security Advisory
...
Security Advisory
...
๐จ CVE-2026-91935
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
๐@cveNotify
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
๐@cveNotify
GitHub
SSRF + LLM API key exfiltration via user-controlled basepath / baseUrl in 8 chat-model nodes
### Summary
Flowise chat-model nodes accept an attacker-controlled `basepath` / `baseUrl` input and pass it **directly** into the underlying LangChain SDK as the LLM provider's `baseURL`, by...
Flowise chat-model nodes accept an attacker-controlled `basepath` / `baseUrl` input and pass it **directly** into the underlying LangChain SDK as the LLM provider's `baseURL`, by...
๐จ CVE-2026-91936
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
๐@cveNotify
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
๐@cveNotify
GitHub
Script injection in Docker image build workflows allows secret theft
### Summary
8 script injection vulnerabilities across 3 Docker image build workflows allow a user with write access to steal AWS credentials and Docker Hub tokens by injecting shell commands thr...
8 script injection vulnerabilities across 3 Docker image build workflows allow a user with write access to steal AWS credentials and Docker Hub tokens by injecting shell commands thr...
๐จ CVE-2026-91937
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
๐@cveNotify
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
๐@cveNotify
GitHub
Cross-Session Data Leakage via NoSQL Injection in MongoDBMemory Node
### Summary
The `MongoDBMemory` node (MongoDB Atlas Chat Memory) in Flowise fails to sanitize the `overrideConfig.sessionId` parameter before using it as a MongoDB query value. An unauthenticate...
The `MongoDBMemory` node (MongoDB Atlas Chat Memory) in Flowise fails to sanitize the `overrideConfig.sessionId` parameter before using it as a MongoDB query value. An unauthenticate...
๐จ CVE-2026-91938
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
๐@cveNotify
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
๐@cveNotify
GitHub
SSRF bypass via Cheerio/Playwright/Puppeteer document loaders โ not covered by httpSecurity deny list
## Summary
The Cheerio, Playwright, and Puppeteer document loader nodes fetch user-provided URLs without calling `checkDenyList()` or using `secureFetch`. They instantiate LangChain's built-...
The Cheerio, Playwright, and Puppeteer document loader nodes fetch user-provided URLs without calling `checkDenyList()` or using `secureFetch`. They instantiate LangChain's built-...
๐จ CVE-2026-91940
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
๐@cveNotify
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
๐@cveNotify
GitHub
Arbitrary file write via unconfined PDFContentScrapingStrategy fields in untrusted config bodies
The Docker API loads request-body configs with Provenance.UNTRUSTED. _filter_untrusted_fields (crawl4ai/async_configs.py) is meant to drop unsafe fields, but it fails open: when a type has no entry...
๐จ CVE-2026-91941
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
๐@cveNotify
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
๐@cveNotify
GitHub
Denial of Service in PDFContentScrapingStrategy: unbounded remote PDF size and page count
### Summary
When an untrusted client selects `PDFContentScrapingStrategy` on the Docker
API, the server downloads and parses a remote PDF with no limit on file size,
page count, or (by default) ...
When an untrusted client selects `PDFContentScrapingStrategy` on the Docker
API, the server downloads and parses a remote PDF with no limit on file size,
page count, or (by default) ...
๐จ CVE-2026-91942
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
๐@cveNotify
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
๐@cveNotify
GitHub
XSS in Docker Playground: crawl results rendered via innerHTML; PDF pipeline emits unescaped HTML
### Summary
The Docker Playground UI displays crawl results by assigning untrusted text to
`element.innerHTML`, which re-parses it as HTML. Combined with the PDF text
pipeline emitting unescaped...
The Docker Playground UI displays crawl results by assigning untrusted text to
`element.innerHTML`, which re-parses it as HTML. Combined with the PDF text
pipeline emitting unescaped...
๐จ CVE-2026-91943
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
๐@cveNotify
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
๐@cveNotify
GitHub
SSRF in PDFContentScrapingStrategy: PDF download follows redirects and bypasses egress SSRF controls
### Summary
The Docker API server validates the destination of a crawl's *seed* URL, but
`PDFContentScrapingStrategy` re-downloads the target with Python `requests`
(`allow_redirects=True`) ...
The Docker API server validates the destination of a crawl's *seed* URL, but
`PDFContentScrapingStrategy` re-downloads the target with Python `requests`
(`allow_redirects=True`) ...
๐จ CVE-2026-91944
crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.
๐@cveNotify
crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.
๐@cveNotify
GitHub
DOM-based XSS in Docker Playground UI leads to operator API-token theft
# [SECURITY] DOM-based XSS in the Docker Playground UI โ operator API-token theft โ full server takeover
**Component:** `deploy/docker` โ Playground UI (`deploy/docker/static/playground/index.ht...
**Component:** `deploy/docker` โ Playground UI (`deploy/docker/static/playground/index.ht...
๐จ CVE-2026-91946
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
๐@cveNotify
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
๐@cveNotify
GitHub
[winpr,utils] initialize wStream buffer with zero ยท FreeRDP/FreeRDP@483c938
FreeRDP is a free remote desktop protocol library and clients - [winpr,utils] initialize wStream buffer with zero ยท FreeRDP/FreeRDP@483c938
๐จ CVE-2026-91947
FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
๐@cveNotify
FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
๐@cveNotify
GitHub
FreeRDP server DRDYNVC parser use-after-free during concurrent channel close
# FreeRDP server DRDYNVC parser use-after-free during concurrent channel close
Discovery credit: Bynario Atlas
CVSS v3.1 (standalone root cause): `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H...
Discovery credit: Bynario Atlas
CVSS v3.1 (standalone root cause): `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H...
๐จ CVE-2026-91948
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
๐@cveNotify
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
๐@cveNotify
GitHub
Fix for #13102 ยท FreeRDP/FreeRDP@40d9202
This patch fixes the case where packet channels are bigger than 1600 bytes and used
by the channel PDU tracker. In theory WTSVirtualChannelRead can not read more than
CHANNEL_CHUNK_LENGTH bytes, so...
by the channel PDU tracker. In theory WTSVirtualChannelRead can not read more than
CHANNEL_CHUNK_LENGTH bytes, so...
๐จ CVE-2026-91949
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
๐@cveNotify
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
๐@cveNotify
GitHub
FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS
# FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS
Discovery credit: Bynario Atlas
CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N` (9.3, Cr...
Discovery credit: Bynario Atlas
CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N` (9.3, Cr...
๐จ CVE-2026-91950
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
๐@cveNotify
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
๐@cveNotify
GitHub
RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard
### Summary
FreeRDP's RDPDR channel packet dump routine (`rdpdr_dump_packet` in `libfreerdp/utils/rdpdr_utils.c`) performs an out-of-bounds read (CWE-125) in the `PAKID_CORE_CLIENT_NAME` cas...
FreeRDP's RDPDR channel packet dump routine (`rdpdr_dump_packet` in `libfreerdp/utils/rdpdr_utils.c`) performs an out-of-bounds read (CWE-125) in the `PAKID_CORE_CLIENT_NAME` cas...
๐จ CVE-2026-91951
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
๐@cveNotify
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
๐@cveNotify
GitHub
Out-of-bounds write in urb_send_current_frame_number_result (urbdrc client channel)
## Summary
A malicious or compromised RDP server can make a FreeRDP client write 4 bytes past the end of a
16 byte heap allocation by sending a single 28 byte USB redirection message.
`urb_s...
A malicious or compromised RDP server can make a FreeRDP client write 4 bytes past the end of a
16 byte heap allocation by sending a single 28 byte USB redirection message.
`urb_s...