<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:13:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292988</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292988</link>
      <description>EUVD-2026-292988</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292988</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41277</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41277</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint behaves as an implicit UPSERT operation. This enables overwriting existing DocumentStore objects. In multi-workspace or multi-tenant deployments, this can lead to cross-workspace object takeover and broken object-level authorization (IDOR), allowing an attacker to reassign or modify DocumentStore objects belonging to other workspaces. This vulnerability is fixed in 3.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint behaves as an implicit UPSERT operation. This enables overwriting existing DocumentStore objects. In multi-workspace or multi-tenant deployments, this can lead to cross-workspace object takeover and broken object-level authorization (IDOR), allowing an attacker to reassign or modify DocumentStore objects belonging to other workspaces. This vulnerability is fixed in 3.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41277</guid>
    </item>
    <item>
      <title>GHSA-3prp-9gf7-4rxx — Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3prp-9gf7-4rxx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;### Summary
A Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities.&lt;/p&gt;
&lt;p&gt;Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint behaves as an implicit UPSERT operation. This enables overwriting existing DocumentStore objects.&lt;/p&gt;
&lt;p&gt;In multi-workspace or multi-tenant deployments, this can lead to cross-workspace object takeover and broken object-level authorization (IDOR), allowing an attacker to reassign or modify DocumentStore objects belonging to other workspaces.&lt;/p&gt;
&lt;p&gt;### Details
The DocumentStore entity defines a globally unique primary key:&lt;/p&gt;
&lt;p&gt;```typescript
@PrimaryGeneratedColumn(&amp;#39;uuid&amp;#39;)
id: string
```&lt;/p&gt;
&lt;p&gt;The create logic is implemented as:
```typescript
const documentStore = repo.create(newDocumentStore)
const dbResponse = await repo.save(documentStore)
```&lt;/p&gt;
&lt;p&gt;Here is no DTO allowlist or field filtering before persistence. The entire request body is mapped directly to the entity.
TypeORM save() behavior:&lt;/p&gt;
&lt;p&gt;1. If the primary key (id) exists → UPDATE
2. If not → INSERT&lt;/p&gt;
&lt;p&gt;Because id is accepted from the client, the create endpoint effectively functions as an UPSERT endpoint.&lt;/p&gt;
&lt;p&gt;This allows an authenticated user to submit:&lt;/p&gt;
&lt;p&gt;```json
{
  &amp;#34;id&amp;#34;: &amp;#34;&amp;lt;existing_store_id&amp;gt;&amp;#34;,
  &amp;#34;name&amp;#34;: &amp;#34;modified&amp;#34;,
  &amp;#34;description&amp;#34;: &amp;#34;modified&amp;#34;,
  &amp;#34;status&amp;#34;: &amp;#34;SYNC&amp;#34;,
  &amp;#34;embeddingConfig&amp;#34;: &amp;#34;...&amp;#34;,
  &amp;#34;vectorStoreConfig&amp;#34;: &amp;#34;...&amp;#34;,
  &amp;#34;recordManagerConfig&amp;#34;: &amp;#34;...&amp;#34;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;### Summary
A Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities.&lt;/p&gt;
&lt;p&gt;Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint behaves as an implicit UPSERT operation. This enables overwriting existing DocumentStore objects.&lt;/p&gt;
&lt;p&gt;In multi-workspace or multi-tenant deployments, this can lead to cross-workspace object takeover and broken object-level authorization (IDOR), allowing an attacker to reassign or modify DocumentStore objects belonging to other workspaces.&lt;/p&gt;
&lt;p&gt;### Details
The DocumentStore entity defines a globally unique primary key:&lt;/p&gt;
&lt;p&gt;```typescript
@PrimaryGeneratedColumn(&amp;#39;uuid&amp;#39;)
id: string
```&lt;/p&gt;
&lt;p&gt;The create logic is implemented as:
```typescript
const documentStore = repo.create(newDocumentStore)
const dbResponse = await repo.save(documentStore)
```&lt;/p&gt;
&lt;p&gt;Here is no DTO allowlist or field filtering before persistence. The entire request body is mapped directly to the entity.
TypeORM save() behavior:&lt;/p&gt;
&lt;p&gt;1. If the primary key (id) exists → UPDATE
2. If not → INSERT&lt;/p&gt;
&lt;p&gt;Because id is accepted from the client, the create endpoint effectively functions as an UPSERT endpoint.&lt;/p&gt;
&lt;p&gt;This allows an authenticated user to submit:&lt;/p&gt;
&lt;p&gt;```json
{
  &amp;#34;id&amp;#34;: &amp;#34;&amp;lt;existing_store_id&amp;gt;&amp;#34;,
  &amp;#34;name&amp;#34;: &amp;#34;modified&amp;#34;,
  &amp;#34;description&amp;#34;: &amp;#34;modified&amp;#34;,
  &amp;#34;status&amp;#34;: &amp;#34;SYNC&amp;#34;,
  &amp;#34;embeddingConfig&amp;#34;: &amp;#34;...&amp;#34;,
  &amp;#34;vectorStoreConfig&amp;#34;: &amp;#34;...&amp;#34;,
  &amp;#34;recordManagerConfig&amp;#34;: &amp;#34;...&amp;#34;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3prp-9gf7-4rxx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1145 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</guid>
    </item>
  </channel>
</rss>
