<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:47:31.267617+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-325661</id>
    <title>EUVD-2026-325661</title>
    <updated>2026-10-04T21:47:31.270489+00:00</updated>
    <content>EUVD-2026-325661</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-325661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46440</id>
    <title>fkie_cve-2026-46440</title>
    <updated>2026-10-04T21:47:31.270521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-php6-83fg-gw3g</id>
    <title>GHSA-php6-83fg-gw3g — FlowiseAI Exposes Basic Auth Credentials via API</title>
    <updated>2026-10-04T21:47:31.270561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise</p>
<p>**Detection Method:** Kolega.dev Deep Code Scan</p>
<p>| Attribute | Value |
|---|---|
| Severity | Medium |
| CWE | CWE-522 (Insufficiently Protected Credentials) |
| Location | packages/server/src/enterprise/controllers/account.controller.ts:128-135 |
| Practical Exploitability | Medium |
| Developer Approver | faizan@kolega.ai |</p>
<p>### Description
The checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison.</p>
<p>### Affected Code
```
public async checkBasicAuth(req: Request, res: Response) {
    const { username, password } = req.body
    if (username === process.env.FLOWISE_USERNAME &amp;&amp; password === process.env.FLOWISE_PASSWORD) {
        return res.json({ message: 'Authentication successful' })
```</p>
<p>### Evidence
Credentials are sent in plaintext in request body and compared directly without hashing. No rate limiting prevents brute force attacks. The endpoint returns different messages for success/failure, enabling enumeration.</p>
<p>### Impact
Credential brute-forcing - attackers can attempt unlimited username/password combinations against the basic auth system. Successful attacks grant access to the application.</p>
<p>### Recommendation
1) Implement rate limiting on this endpoint, 2) Use constant-time comparison to prevent timing attacks, 3) Consider using hashed comparison, 4) Return generic error messages, 5) Add logging for failed attempts.</p>
<p>### Notes
The checkBasicAuth endpoint at line 128-135 has multiple security issues: (1) No rate l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-php6-83fg-gw3g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554</id>
    <title>WID-SEC-W-2026-1554 — Flowise: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-04T21:47:31.270607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um Code auszuführen, Objekte anderer Benutzer zu übernehmen, Informationen offenzulegen und weitere, nicht näher genannte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554"/>
  </entry>
</feed>
