<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T19:41:45.553782+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329267</id>
    <title>EUVD-2026-329267</title>
    <updated>2026-10-04T19:41:45.609581+00:00</updated>
    <content>EUVD-2026-329267</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56268</id>
    <title>fkie_cve-2026-56268</title>
    <updated>2026-10-04T19:41:45.609637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default), the endpoint returns not only the chatflows bound to the supplied API key but also all chatflows across every workspace that have no API key assigned, because the underlying query lacks any workspace filter. An attacker with a valid API key for one workspace can therefore retrieve the full ChatFlow configuration (including flowData with system prompts and node configurations, chatbotConfig, apiConfig, and credential IDs) of unprotected chatflows belonging to other workspaces.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c2c9-mfw7-p8hw</id>
    <title>GHSA-c2c9-mfw7-p8hw — Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows</title>
    <updated>2026-10-04T19:41:45.609711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise</p>
<p>## Summary</p>
<p>The `/api/v1/chatflows/apikey/:apikey` endpoint (whitelisted, accessible with API key auth only) returns all chatflows bound to the provided API key AND all chatflows across the entire system that have no API key assigned. This crosses workspace boundaries, allowing a user in Workspace A who has a valid API key to read the full configuration (including flowData, chatbotConfig, system prompts, and node configurations) of chatflows from Workspace B, Workspace C, and all other workspaces, as long as those chatflows have no API key assigned.</p>
<p>## Details</p>
<p>The controller at `packages/server/src/controllers/chatflows/index.ts:90-107` validates the API key and calls the service:</p>
<p>```typescript
const getChatflowByApiKey = async (req: Request, res: Response, next: NextFunction) =&gt; {
    try {
        const apikey = await apiKeyService.getApiKey(req.params.apikey)
        if (\!apikey) {
            return res.status(401).send("Unauthorized")
        }
        const apiResponse = await chatflowsService.getChatflowByApiKey(apikey.id, req.query.keyonly)
        return res.json(apiResponse)  // Returns full chatflow objects with flowData
    } catch (error) {
        next(error)
    }
}
```</p>
<p>The service at `packages/server/src/services/chatflows/index.ts:223-245` builds the database query:</p>
<p>```typescript
const getChatflowByApiKey = async (apiKeyId: string, keyonly?: unknown): Promise&lt;any&gt; =&gt; {
    const appServer = getRunningExpressApp()
    let query = appServer.AppDataSource…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c2c9-mfw7-p8hw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554</id>
    <title>WID-SEC-W-2026-1554 — Flowise: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-04T19:41:45.609855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um Code auszuführen, Objekte anderer Benutzer zu übernehmen, Informationen offenzulegen und weitere, nicht näher genannte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554"/>
  </entry>
</feed>
