<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T02:46:43.866623+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275113</id>
    <title>EUVD-2026-275113</title>
    <updated>2026-10-08T02:46:43.869816+00:00</updated>
    <content>EUVD-2026-275113</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30823</id>
    <title>fkie_cve-2026-30823</title>
    <updated>2026-10-08T02:46:43.869863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30823"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cwc3-p92j-g7qm</id>
    <title>GHSA-cwc3-p92j-g7qm — Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration</title>
    <updated>2026-10-08T02:46:43.869896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise</p>
<p>### Summary
The Flowise platform has a critical Insecure Direct Object Reference (IDOR) vulnerability combined with a Business Logic Flaw in the PUT /api/v1/loginmethod endpoint.</p>
<p>While the endpoint requires authentication, it fails to validate if the authenticated user has ownership or administrative rights over the target organizationId. This allows any low-privileged user (including "Free" plan users) to:</p>
<p>1. Overwrite the SSO configuration of any other organization.
2. Enable "Enterprise-only" features (SSO/SAML) without a license.
3. Perform Account Takeover  by redirecting the authentication flow.</p>
<p>### Details
The backend accepts the organizationId parameter from the JSON body and updates the database record corresponding to that ID. There is no middleware or logic check to ensure request.user.organizationId === body.organizationId.</p>
<p>### PoC
Prerequisites:
1. The attacker creates a standard "Free" account and obtains a valid JWT token (Cookie/Header).
2. The attacker identifies the target organizationId (e.g., bd2b74e0-e0cd-4bb5-ba98-3cc2ae683d5d).</p>
<p>**Step-by-Step Exploitation**: The attacker sends the following PUT request to overwrite the victim's Google SSO configuration.</p>
<p>**Request**:</p>
<p>```http
PUT /api/v1/loginmethod HTTP/2
Host: cloud.flowiseai.com
Cookie: token=&lt;ATTACKER_JWT_TOKEN&gt;
Content-Type: application/json
Accept: application/json</p>
<p>{
  "organizationId": "bd2b74e0-e0cd-4bb5-ba98-3cc2ae683d5d",
  "userId": "6ab311fa-0d0a-4bd6-996e-4ae721377fb2", 
  "providers…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cwc3-p92j-g7qm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0626</id>
    <title>WID-SEC-W-2026-0626 — Flowise: Mehrere Schwachstellen</title>
    <updated>2026-10-08T02:46:43.869945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um sich erweiterte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0626"/>
  </entry>
</feed>
