<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:32:03.499113+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344200</id>
    <title>EUVD-2026-344200</title>
    <updated>2026-10-02T20:32:03.562653+00:00</updated>
    <content>EUVD-2026-344200</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344200"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69259</id>
    <title>fkie_cve-2026-69259</title>
    <updated>2026-10-02T20:32:03.562702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x3hf-7cj6-3r4m</id>
    <title>GHSA-x3hf-7cj6-3r4m — Flowise RCE via SQLite Record Manager Node</title>
    <updated>2026-10-02T20:32:03.562760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise, npm: flowise-components</p>
<p>=============================================================================
                                                            Security Advisory
                                                                       elttam</p>
<p>Topic:          Flowise RCE via SQLite Record Manager Node</p>
<p>Module:         FlowiseAI/Flowise
Disclosed:      24-Apr-2026
Credits:        Alex Brown
Affects:        `FlowiseAI/Flowise 3.1.2`</p>
<p># I.   Background</p>
<p>Flowise AI is an open-source, low-code platform for building AI applications—such as chatbots, workflows, and autonomous agents—through an intuitive drag-and-drop interface, minimising the need for extensive coding.</p>
<p>Flowise allows users to connect to a local SQLite database for record management of Upsert Vector Store operations.</p>
<p># II.  Problem Description</p>
<p>The database path for the "SQLite Record Manager" node could be overridden using the `additionalConfig` input, as demonstrated in the following code snippet.</p>
<p>[https://github.com/FlowiseAI/Flowise/blob/flowise-components@3.1.2/packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts](https://github.com/FlowiseAI/Flowise/blob/flowise-components%403.1.2/packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts)
```ts
class SQLiteRecordManager_RecordManager implements INode {
    ...
    async init(nodeData: INodeData, _: string, options: ICommonObject): Promise&lt;any&gt; {
        const _tableName = nodeData.inputs?.tableName as string…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x3hf-7cj6-3r4m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</id>
    <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:32:03.562941+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589"/>
  </entry>
</feed>
