Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.43% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports… | |
| Analizada | Crítica (9.4) | 1.0% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve… | |
| Analizada | Crítica (9.2) | 0.72% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string =… | |
| Analizada | Crítica (9.4) | 0.69% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching… | |
| Analizada | Crítica (9) | 0.66% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2 sandbox. To build that code, they inserted a user-controlled baseURL value straight… | |
| Analizada | Alta (7.2) | 0.54% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with unrelated permissions could call GET… | |
| Analizada | Crítica (9) | 2.7% | 💥 Exploit | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in… | |
| Analizada | Alta (8.5) | 0.57% | — | Flowiseai Flowise | 4/8/2026 | 14/9/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF… | |
| Analizada | Crítica (9.3) | 0.66% | — | Flowiseai Flowise | 12/7/2026 | 14/7/2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the… | |
| Aplazada | Media (4.9) | 0.50% | — | FaissAIFlowise SimplestoreAIFlowiseai FlowiseAI | 8/7/2026 | 9/7/2026 | Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations, potentially enabling code execution or… | |
| Analizada | Crítica (9.3) | 0.53% | — | Flowiseai Flowise | 30/6/2026 | 6/7/2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible… | |
| Analizada | Media (6.9) | 0.18% | — | Flowiseai Flowise | 30/6/2026 | 6/7/2026 | Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise restrictive default CORS configuration… | |
| Analizada | Baja (2.3) | 1.6% | 💥 Exploit | Flowiseai Flowise | 28/6/2026 | 6/7/2026 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can… | |
| Modificada | Crítica (10) | 1.2% | 💥 PoC | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code… | |
| Analizada | Crítica (9.3) | 1.1% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks… | |
| Analizada | Alta (8.6) | 0.38% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even… | |
| Analizada | Crítica (9.3) | 4.4% | 💥 Exploit | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an… | |
| Analizada | Crítica (9.3) | 0.90% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code… | |
| Analizada | Alta (8.7) | 0.47% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the… | |
| Analizada | Crítica (9.3) | 0.68% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without… | |
| Modificada | Alta (8.7) | 1.6% | 💥 Exploit | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup path constructed without the orgId is… | |
| Analizada | Media (5.6) | 0.10% | — | Flowiseai Flowise | 24/6/2026 | 26/6/2026 | Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario. | |
| Analizada | Alta (8.7) | 2.0% | 💥 Exploit | Flowiseai Flowise | 24/6/2026 | 26/6/2026 | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter.… | |
| Analizada | Media (4.3) | 0.13% | — | Flowiseai Flowise | 24/6/2026 | 26/6/2026 | Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives the AES-256-CBC key used to encrypt… | |
| Analizada | Alta (8.5) | 0.52% | — | Flowiseai Flowise | 24/6/2026 | 30/9/2026 | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including… |