Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.27% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows selected solely by an attacker-supplied chatflowid, and… | |
| Aplazada | Alta (7.6) | 0.23% | — | Flowiseai FlowiseAIFlowise ComponentsAI | 26/9/2026 | 30/9/2026 | Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in several code paths: getAllOpenaiAssistants/getSingleOpenaiAssistant (GET /api/v1/openai-assistants… | |
| Aplazada | Alta (8.7) | 0.27% | — | Flowiseai FlowiseAI | 26/9/2026 | 26/9/2026 | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues mount is protected only by the verifyTokenForBullMQDashboard middleware,… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any configured SSO provider. Attackers can gain complete account access including chatflows,… | |
| Aplazada | Crítica (9.2) | 0.37% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored… | |
| Aplazada | Alta (7.5) | 0.22% | — | Flowiseai FlowiseAI | 26/9/2026 | 30/9/2026 | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts,… | |
| Pendiente de análisis | Alta (7.6) | 0.37% | — | CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as… | |
| Pendiente de análisis | Alta (8.3) | 0.46% | — | Flowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | Flowiseai FlowiseAI | 15/9/2026 | 16/9/2026 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform… | |
| Pendiente de análisis | Alta (7.6) | 0.35% | — | Flowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from… | |
| Pendiente de análisis | Crítica (9) | 0.73% | — | Flowiseai FlowiseAI | 15/9/2026 | 16/9/2026 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute… | |
| Aplazada | Alta (8.7) | 0.47% | — | MongodbAIFlowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection. | |
| Pendiente de análisis | Alta (8.7) | 0.39% | — | Flowiseai FlowiseAI | 15/9/2026 | 19/9/2026 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts. | |
| Aplazada | Crítica (9) | 0.68% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server. | |
| Aplazada | Alta (7.7) | 0.40% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by… | |
| Aplazada | Alta (7.6) | 0.35% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets. | |
| Analizada | Baja (2.1) | 0.41% | — | Flowiseai Flowise | 13/9/2026 | 16/9/2026 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The… | |
| Analizada | Media (6.3) | 0.48% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known… | |
| Analizada | Media (6.1) | 0.37% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The… | |
| Analizada | Media (6) | 0.34% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain… | |
| Analizada | Crítica (9.8) | 1.1% | — | Flowiseai Flowise | 10/9/2026 | 15/9/2026 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint | |
| Analizada | Alta (7.1) | 0.41% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud… | |
| Analizada | Media (6.3) | 0.33% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID,… | |
| Analizada | Crítica (9) | 0.83% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute… | |
| Analizada | Crítica (9) | 1.1% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment… |