<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T04:10:12.230237+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330018</id>
    <title>EUVD-2026-330018</title>
    <updated>2026-10-06T04:10:12.232769+00:00</updated>
    <content>EUVD-2026-330018</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71332</id>
    <title>fkie_cve-2025-71332</title>
    <updated>2026-10-06T04:10:12.232801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including blind and error-based extraction of data from the credential table.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-71332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9c4c-g95m-c8cp</id>
    <title>GHSA-9c4c-g95m-c8cp — FlowiseDB vulnerable to SQL Injection by authenticated users</title>
    <updated>2026-10-06T04:10:12.232833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise</p>
<p>### Summary
import functions are vulnerable.
* [importChatflows](https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/services/chatflows/index.ts#L219)
* [importTools](https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/services/tools/index.ts#L85)
* [importVariables](https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/services/variables/index.ts)</p>
<p>### Details
**Authenticated user** can call importChatflows API, import json file such as `AllChatflows.json`.
but Due to insufficient validation to chatflow.id in importChatflows API, 2 issues arise.</p>
<p>**Issue 1 (Bug Type)**
1. Malicious user creates `AllChatflows.json` file by adding `../` and arbitrary path to the chatflow.id of the json file.
    ```json
    {
      "Chatflows": [
        {
          "id": "../../../../../../apikey",
          "name": "clickme",
          "flowData": "{}"
        }
      ]
    }
    ```
2. Victim download this file, and import this to flowise.
3. When victim click created chatflow, victim access to flowise:3000/canvas/{chatflow.id}.</p>
<p>**Issue 2 (Vulnerability Type)**
importChatflows API use unsafe SQL Query.</p>
<p>```javascript
// packages/server/src/services/chatflows/index.ts
const importChatflows = async (newChatflows: Partial&lt;ChatFlow&gt;[]): Promise&lt;any&gt; =&gt; {
        try {
        const appServer = getRunningExpressApp()</p>
<p>// step 1 - check whether file chatflows array is zero
        if (newChatflows.length == 0) return</p>
<p>// step 2 - check…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9c4c-g95m-c8cp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0717</id>
    <title>WID-SEC-W-2025-0717 — Flowise: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-06T04:10:12.232896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Flowise ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0717"/>
  </entry>
</feed>
