<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 07:19:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292958</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292958</link>
      <description>EUVD-2026-292958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292958</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41138</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41138</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python code without any sanitization. This vulnerability is fixed in 3.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python code without any sanitization. This vulnerability is fixed in 3.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41138</guid>
    </item>
    <item>
      <title>GHSA-f228-chmx-v6j6 — Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Panda…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f228-chmx-v6j6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;“AirtableAgent” is an agent function provided by FlowiseAI that retrieves search results by accessing private datasets from airtable.com. “AirtableAgent” uses Python, along with `Pyodide` and `Pandas`, to get and return results.&lt;/p&gt;
&lt;p&gt;The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python code without any sanitization.&lt;/p&gt;
&lt;p&gt;**The point is that an attacker can bypass the intended behavior of the LLM and trigger Remote Code Execution through a simple prompt injection.**&lt;/p&gt;
&lt;p&gt;### About Airtable&lt;/p&gt;
&lt;p&gt;The `airtable.ts` function retrieves and processes user datasets stored on Airtable.com through its API.&lt;/p&gt;
&lt;p&gt;![pic1](https://drive.google.com/uc?id=1pKzk2leZ_w6Zb1rL3Rm0xkQr3ty1jom9)
![pic2](https://drive.google.com/uc?id=1pConjaiW2eeWJpcHnx1LTp3_CYn846u8)
The usage of Airtable is as shown in the image above. After creating a Chatflow like above, you can ask data-related questions using prompts and receive answers.&lt;/p&gt;
&lt;p&gt;![pic3](https://drive.google.com/uc?id=1S6cIznhnuEjXJjRHCX32Av6QkgYQza6Q)&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```jsx
// packages/components/nodes/agents/AirtableAgent/AirtableAgent.ts
  let base64String = Buffer.from(JSON.stringify(airtableData)).toString(&amp;#39;base64&amp;#39;)&lt;/p&gt;
&lt;p&gt;const loggerHandler = new ConsoleCallbackHandler(options.logger)
  const callbacks = await additionalCallbacks(nodeData, options)&lt;/p&gt;
&lt;p&gt;const pyodide = await LoadPyodide()&lt;/p&gt;
&lt;p&gt;// First load the csv file and get the dataframe dictionary of column types
  //…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;“AirtableAgent” is an agent function provided by FlowiseAI that retrieves search results by accessing private datasets from airtable.com. “AirtableAgent” uses Python, along with `Pyodide` and `Pandas`, to get and return results.&lt;/p&gt;
&lt;p&gt;The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python code without any sanitization.&lt;/p&gt;
&lt;p&gt;**The point is that an attacker can bypass the intended behavior of the LLM and trigger Remote Code Execution through a simple prompt injection.**&lt;/p&gt;
&lt;p&gt;### About Airtable&lt;/p&gt;
&lt;p&gt;The `airtable.ts` function retrieves and processes user datasets stored on Airtable.com through its API.&lt;/p&gt;
&lt;p&gt;![pic1](https://drive.google.com/uc?id=1pKzk2leZ_w6Zb1rL3Rm0xkQr3ty1jom9)
![pic2](https://drive.google.com/uc?id=1pConjaiW2eeWJpcHnx1LTp3_CYn846u8)
The usage of Airtable is as shown in the image above. After creating a Chatflow like above, you can ask data-related questions using prompts and receive answers.&lt;/p&gt;
&lt;p&gt;![pic3](https://drive.google.com/uc?id=1S6cIznhnuEjXJjRHCX32Av6QkgYQza6Q)&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```jsx
// packages/components/nodes/agents/AirtableAgent/AirtableAgent.ts
  let base64String = Buffer.from(JSON.stringify(airtableData)).toString(&amp;#39;base64&amp;#39;)&lt;/p&gt;
&lt;p&gt;const loggerHandler = new ConsoleCallbackHandler(options.logger)
  const callbacks = await additionalCallbacks(nodeData, options)&lt;/p&gt;
&lt;p&gt;const pyodide = await LoadPyodide()&lt;/p&gt;
&lt;p&gt;// First load the csv file and get the dataframe dictionary of column types
  //…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f228-chmx-v6j6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1145 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</guid>
    </item>
  </channel>
</rss>
