<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:00:51.641998+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-310029</id>
    <title>EUVD-2026-310029</title>
    <updated>2026-10-04T13:00:51.644437+00:00</updated>
    <content>EUVD-2026-310029</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-310029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43995</id>
    <title>fkie_cve-2026-43995</title>
    <updated>2026-10-04T13:00:51.644468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. These tools include (1) OpenAPIToolkit/OpenAPIToolkit.ts, (2) WebScraperTool/WebScraperTool.ts, (3) MCP/core.ts, and (4) Arxiv/core.ts. This vulnerability is fixed in 3.1.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqvm-66q4-vf5c</id>
    <title>GHSA-qqvm-66q4-vf5c — Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)</title>
    <updated>2026-10-04T13:00:51.644501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise, npm: flowise-components</p>
<p>### Summary</p>
<p>Flowise introduced SSRF protections through a centralized HTTP security wrapper (`httpSecurity.ts`) that implements deny-list validation and IP pinning logic.</p>
<p>However, multiple tool implementations directly import and invoke raw HTTP clients (`node-fetch`, `axios`Instead of using the secured wrapper.</p>
<p>Because enforcement is neither mandatory nor centralized, these tools bypass SSRF mitigation entirely, restoring full SSRF capability even after the patch.</p>
<p>This issue is distinct from specification trust issues and represents incomplete mitigation of previously addressed SSRF vulnerabilities.</p>
<p>### Details
**Intended Security Model:**</p>
<p>All outbound HTTP requests should pass through the centralized validation layer implemented in:</p>
<p>```
packages/components/src/httpSecurity.ts
```</p>
<p>This layer performs:</p>
<p>- `HTTP_DENY_LIST` enforcement
- IP resolution validation
- IP pinning
- Loopback blocking</p>
<p>**Observed Implementation Gap:**</p>
<p>Multiple tools bypass this layer and import HTTP libraries directly.</p>
<p>Examples include:</p>
<p>- `packages/components/nodes/tools/OpenAPIToolkit/OpenAPIToolkit.ts`
- `packages/components/nodes/tools/WebScraperTool/WebScraperTool.ts`
- `packages/components/nodes/tools/MCP/core.ts`
- `packages/components/nodes/tools/Arxiv/core.ts`</p>
<p>These files directly execute:</p>
<p>```
importfetchfrom'node-fetch'
```</p>
<p>or invoke `axios` without passing through the centralized validation wrapper.</p>
<p>Because there is no global interceptor or enforcement mechanism, outbound req…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqvm-66q4-vf5c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</id>
    <title>WID-SEC-W-2026-1145 — Flowise: Mehrere Schwachstellen</title>
    <updated>2026-10-04T13:00:51.644561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145"/>
  </entry>
</feed>
