<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:54:14.123319+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-325846</id>
    <title>EUVD-2026-325846</title>
    <updated>2026-10-04T01:54:14.174006+00:00</updated>
    <content>EUVD-2026-325846</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-325846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46442</id>
    <title>fkie_cve-2026-46442</title>
    <updated>2026-10-04T01:54:14.174040+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is not configured — the common deployment case — Flowise executes this code inside a NodeVM sandbox. This sandbox can be escaped, allowing an attacker to reach the host process object and execute system commands via child_process. The result is authenticated remote code execution on the Flowise server host. This issue has been patched in version 3.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46442"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9rvc-vf7m-pgm2</id>
    <title>GHSA-9rvc-vf7m-pgm2 — FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape</title>
    <updated>2026-10-04T01:54:14.174079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise</p>
<p>### Summary</p>
<p>`POST /api/v1/node-custom-function` lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the `Custom JS Function` node.</p>
<p>When `E2B_APIKEY` is not configured — the common deployment case — Flowise executes this code inside a `NodeVM` sandbox. This sandbox can be escaped, allowing an attacker to reach the host `process` object and execute system commands via `child_process`.</p>
<p>The result is authenticated remote code execution on the Flowise server host. CVSS v3.1: `AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H` = **9.9 Critical**.</p>
<p>### Details</p>
<p>Two distinct security boundaries are violated.</p>
<p>**1. Missing route-level authorization**</p>
<p>`packages/server/src/routes/node-custom-functions/index.ts` registers the endpoint with no permission middleware:</p>
<p>```ts
router.post('/', nodesRouter.executeCustomFunction)
```</p>
<p>Other sensitive routes in the same codebase use explicit permission gates:</p>
<p>```ts
// packages/server/src/routes/chatflows/index.ts
router.post(
  '/',
  checkAnyPermission('chatflows:create,chatflows:update,agentflows:create,agentflows:update'),
  chatflowsController.saveChatflow
)
```</p>
<p>Global `/api/v1` authentication still applies, so this is not unauthenticated — but any valid session or API key reaches the endpoint without further restriction.</p>
<p>**2. NodeVM sandbox escape**</p>
<p>The endpoint forwards `body.javascriptFunction` through the following chain:</p>
<p>```
POST /api/v1/node-custom-function
  → packages/server/src/c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9rvc-vf7m-pgm2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554</id>
    <title>WID-SEC-W-2026-1554 — Flowise: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-04T01:54:14.174149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um Code auszuführen, Objekte anderer Benutzer zu übernehmen, Informationen offenzulegen und weitere, nicht näher genannte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554"/>
  </entry>
</feed>
