<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:54:24.472153+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344237</id>
    <title>EUVD-2026-344237</title>
    <updated>2026-10-03T22:54:24.538942+00:00</updated>
    <content>EUVD-2026-344237</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-70471</id>
    <title>fkie_cve-2026-70471</title>
    <updated>2026-10-03T22:54:24.538993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime variables are resolved from server environment variables, while the official variables route enforces variables:view. A user or API key that is denied variables:view can call /api/v1/node-custom-function and receive $vars pre-populated with all variables for the workspace, including Variable.name to Variable.value static variables and Variable.name to process.env[Variable.name] runtime variables. This can expose secrets such as database passwords, JWT secrets, SMTP passwords, and cloud keys, depending on the workspace Variables configuration. This issue is fixed in version 3.1.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-70471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8r8h-6vcc-xhrv</id>
    <title>GHSA-8r8h-6vcc-xhrv — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure</title>
    <updated>2026-10-03T22:54:24.539055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise</p>
<p>## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)</p>
<p>### What’s wrong (code locations)</p>
<p>- Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/
    packages/components/src/utils.ts:932
  - Runtime variables are resolved from server environment variables: flowise-src/packages/components/src/utils.ts:976
  - $vars is always injected into the code execution sandbox: flowise-src/packages/components/src/utils.ts:1782
  - The official Variables API is permission-protected (contrast): flowise-src/packages/server/src/routes/variables/
    index.ts:11</p>
<p>### Why it is a privilege boundary bypass</p>
<p>A user/API key might be denied variables:view (and the /api/v1/variables route enforces it), but they can still:</p>
<p>- call /api/v1/node-custom-function (Finding 1)
  - and have $vars pre-populated with all variables for the workspace, including runtime values from process.env</p>
<p>### What data is exposed</p>
<p>Inside the custom JS context, $vars contains a flat map of:</p>
<p>- Variable.name -&gt; Variable.value for static variables, and
  - Variable.name -&gt; process.env[Variable.name] for runtime variables (type === 'runtime')</p>
<p>This can expose secrets such as database passwords, JWT secrets, SMTP passwords, cloud keys, etc., depending on what
  the workspace Variables are configured to map.</p>
<p>### Recommended fix (minimum)</p>
<p>- Do not inject $vars unless the caller is authorized:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8r8h-6vcc-xhrv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</id>
    <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:54:24.539160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589"/>
  </entry>
</feed>
