<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:08:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275115</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275115</link>
      <description>EUVD-2026-275115</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275115</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30821</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30821</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on the MIME types defined in chatbotConfig.fullFileUpload.allowedUploadFileTypes, it implicitly trusts the client-provided Content-Type header (file.mimetype) without verifying the file&amp;#39;s actual content (magic bytes) or extension (file.originalname). Consequently, an attacker can bypass this restriction by spoofing the Content-Type as a permitted type (e.g., application/pdf) while uploading malicious scripts or arbitrary files. Once uploaded via addArrayFilesToStorage, these files persist in backend storage (S3, GCS, or local disk). This vulnerability serves as a critical entry point that, when chained with other features like static hosting or file retrieval, can lead to Stored XSS, malicious file hosting, or Remote Code Execution (RCE). This issue has been patched in version 3.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on the MIME types defined in chatbotConfig.fullFileUpload.allowedUploadFileTypes, it implicitly trusts the client-provided Content-Type header (file.mimetype) without verifying the file&amp;#39;s actual content (magic bytes) or extension (file.originalname). Consequently, an attacker can bypass this restriction by spoofing the Content-Type as a permitted type (e.g., application/pdf) while uploading malicious scripts or arbitrary files. Once uploaded via addArrayFilesToStorage, these files persist in backend storage (S3, GCS, or local disk). This vulnerability serves as a critical entry point that, when chained with other features like static hosting or file retrieval, can lead to Stored XSS, malicious file hosting, or Remote Code Execution (RCE). This issue has been patched in version 3.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30821</guid>
    </item>
    <item>
      <title>GHSA-j8g8-j7fc-43v6 — Flowise has Arbitrary File Upload via MIME Spoofing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j8g8-j7fc-43v6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;### Vulnerability **Description**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;**Vulnerability Overview**
 
- The `/api/v1/attachments/:chatflowId/:chatId` endpoint is listed in `WHITELIST_URLS`, allowing unauthenticated access to the file upload API.
- While the server validates uploads based on the MIME types defined in `chatbotConfig.fullFileUpload.allowedUploadFileTypes`, it implicitly trusts the client-provided `Content-Type` header (`file.mimetype`) without verifying the file&amp;#39;s actual content (magic bytes) or extension (`file.originalname`).
- Consequently, an attacker can bypass this restriction by spoofing the `Content-Type` as a permitted type (e.g., `application/pdf`) while uploading malicious scripts or arbitrary files. Once uploaded via `addArrayFilesToStorage`, these files persist in backend storage (S3, GCS, or local disk). This vulnerability serves as a critical entry point that, when chained with other features like static hosting or file retrieval, can lead to Stored XSS, malicious file hosting, or Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;**Vulnerable Code**&lt;/p&gt;
&lt;p&gt;- Upload Route Definition
    
    https://github.com/FlowiseAI/Flowise/blob/d17c4394a238b49327b493c89feee45f3a20bb91/packages/server/src/routes/attachments/index.ts#L7-L10
    
    ```tsx
    // CREATE
    router.post(&amp;#39;/:chatflowId/:chatId&amp;#39;, getMulterStorage().array(&amp;#39;files&amp;#39;), attachmentsController.createAttachment)
    export default router
    ```
    
- Mount /api/v1/attachments to the global router
    
    https://github.com/FlowiseAI/Flowise/blob…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;### Vulnerability **Description**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;**Vulnerability Overview**
 
- The `/api/v1/attachments/:chatflowId/:chatId` endpoint is listed in `WHITELIST_URLS`, allowing unauthenticated access to the file upload API.
- While the server validates uploads based on the MIME types defined in `chatbotConfig.fullFileUpload.allowedUploadFileTypes`, it implicitly trusts the client-provided `Content-Type` header (`file.mimetype`) without verifying the file&amp;#39;s actual content (magic bytes) or extension (`file.originalname`).
- Consequently, an attacker can bypass this restriction by spoofing the `Content-Type` as a permitted type (e.g., `application/pdf`) while uploading malicious scripts or arbitrary files. Once uploaded via `addArrayFilesToStorage`, these files persist in backend storage (S3, GCS, or local disk). This vulnerability serves as a critical entry point that, when chained with other features like static hosting or file retrieval, can lead to Stored XSS, malicious file hosting, or Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;**Vulnerable Code**&lt;/p&gt;
&lt;p&gt;- Upload Route Definition
    
    https://github.com/FlowiseAI/Flowise/blob/d17c4394a238b49327b493c89feee45f3a20bb91/packages/server/src/routes/attachments/index.ts#L7-L10
    
    ```tsx
    // CREATE
    router.post(&amp;#39;/:chatflowId/:chatId&amp;#39;, getMulterStorage().array(&amp;#39;files&amp;#39;), attachmentsController.createAttachment)
    export default router
    ```
    
- Mount /api/v1/attachments to the global router
    
    https://github.com/FlowiseAI/Flowise/blob…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j8g8-j7fc-43v6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0626 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0626</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um sich erweiterte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um sich erweiterte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0626</guid>
    </item>
  </channel>
</rss>
