<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:47:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-325661</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325661</link>
      <description>EUVD-2026-325661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325661</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46440</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46440</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46440</guid>
    </item>
    <item>
      <title>GHSA-php6-83fg-gw3g — FlowiseAI Exposes Basic Auth Credentials via API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-php6-83fg-gw3g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;**Detection Method:** Kolega.dev Deep Code Scan&lt;/p&gt;
&lt;p&gt;| Attribute | Value |
|---|---|
| Severity | Medium |
| CWE | CWE-522 (Insufficiently Protected Credentials) |
| Location | packages/server/src/enterprise/controllers/account.controller.ts:128-135 |
| Practical Exploitability | Medium |
| Developer Approver | faizan@kolega.ai |&lt;/p&gt;
&lt;p&gt;### Description
The checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison.&lt;/p&gt;
&lt;p&gt;### Affected Code
```
public async checkBasicAuth(req: Request, res: Response) {
    const { username, password } = req.body
    if (username === process.env.FLOWISE_USERNAME &amp;amp;&amp;amp; password === process.env.FLOWISE_PASSWORD) {
        return res.json({ message: &amp;#39;Authentication successful&amp;#39; })
```&lt;/p&gt;
&lt;p&gt;### Evidence
Credentials are sent in plaintext in request body and compared directly without hashing. No rate limiting prevents brute force attacks. The endpoint returns different messages for success/failure, enabling enumeration.&lt;/p&gt;
&lt;p&gt;### Impact
Credential brute-forcing - attackers can attempt unlimited username/password combinations against the basic auth system. Successful attacks grant access to the application.&lt;/p&gt;
&lt;p&gt;### Recommendation
1) Implement rate limiting on this endpoint, 2) Use constant-time comparison to prevent timing attacks, 3) Consider using hashed comparison, 4) Return generic error messages, 5) Add logging for failed attempts.&lt;/p&gt;
&lt;p&gt;### Notes
The checkBasicAuth endpoint at line 128-135 has multiple security issues: (1) No rate l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;**Detection Method:** Kolega.dev Deep Code Scan&lt;/p&gt;
&lt;p&gt;| Attribute | Value |
|---|---|
| Severity | Medium |
| CWE | CWE-522 (Insufficiently Protected Credentials) |
| Location | packages/server/src/enterprise/controllers/account.controller.ts:128-135 |
| Practical Exploitability | Medium |
| Developer Approver | faizan@kolega.ai |&lt;/p&gt;
&lt;p&gt;### Description
The checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison.&lt;/p&gt;
&lt;p&gt;### Affected Code
```
public async checkBasicAuth(req: Request, res: Response) {
    const { username, password } = req.body
    if (username === process.env.FLOWISE_USERNAME &amp;amp;&amp;amp; password === process.env.FLOWISE_PASSWORD) {
        return res.json({ message: &amp;#39;Authentication successful&amp;#39; })
```&lt;/p&gt;
&lt;p&gt;### Evidence
Credentials are sent in plaintext in request body and compared directly without hashing. No rate limiting prevents brute force attacks. The endpoint returns different messages for success/failure, enabling enumeration.&lt;/p&gt;
&lt;p&gt;### Impact
Credential brute-forcing - attackers can attempt unlimited username/password combinations against the basic auth system. Successful attacks grant access to the application.&lt;/p&gt;
&lt;p&gt;### Recommendation
1) Implement rate limiting on this endpoint, 2) Use constant-time comparison to prevent timing attacks, 3) Consider using hashed comparison, 4) Return generic error messages, 5) Add logging for failed attempts.&lt;/p&gt;
&lt;p&gt;### Notes
The checkBasicAuth endpoint at line 128-135 has multiple security issues: (1) No rate l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-php6-83fg-gw3g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1554 — Flowise: Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um Code auszuführen, Objekte anderer Benutzer zu übernehmen, Informationen offenzulegen und weitere, nicht näher genannte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um Code auszuführen, Objekte anderer Benutzer zu übernehmen, Informationen offenzulegen und weitere, nicht näher genannte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1554</guid>
    </item>
  </channel>
</rss>
