<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:38:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329220</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329220</link>
      <description>EUVD-2026-329220</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329220</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56275</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56275</link>
      <description>&lt;p&gt;Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56275</guid>
    </item>
    <item>
      <title>GHSA-9hrv-gvrv-6gf2 — Flowise Execute Flow function has an SSRF vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9hrv-gvrv-6gf2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The attacker provides an intranet address through the base url field configured in the Execute Flow node 
→ Bypass checkDenyList / resolveAndValidate in httpSecurity.ts (not called)
→ Causes the server to initiate an HTTP request to any internal network address, read cloud metadata, or detect internal network services&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1280&amp;#34; height=&amp;#34;860&amp;#34; alt=&amp;#34;9a52a74e6fe2fd78e4962d1d68057fc2&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/20df0006-9129-4886-8928-16d19a617c23&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Then initiate the call:&lt;/p&gt;
&lt;p&gt;```
POST /api/v1/prediction/d6739838-d3b3-43d9-86ff-911a3d757a7e HTTP/1.1
Host: 127.0.0.1:3000
Content-Type: application/json
Authorization: Bearer apikey
Content-Length: 17&lt;/p&gt;
&lt;p&gt;{&amp;#34;question&amp;#34;: &amp;#34;1&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;Server received a request:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1432&amp;#34; height=&amp;#34;172&amp;#34; alt=&amp;#34;f45c757fec408e13739db068252ff21b&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/d3dfe0f5-83ec-4c79-ab32-754382a68d5f&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;And there is an echo:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1280&amp;#34; height=&amp;#34;666&amp;#34; alt=&amp;#34;fa0caf0deb306cfeeea8fdf8941a287e&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/55a94d25-120b-4e9c-9517-46c2fc2b667f&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Fix:
Call secureFetch for verification&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This is a Server-Side Request Forgery (SSRF) vulnerability that may lead to the following risks: 
- Explore Internal Web Applications
- Access sensitive management interfaces
- Leak internal configuration, credentials, or confidential information&lt;/p&gt;
&lt;p&gt;This vulnerability significantly increases the risk of internal service enumeration and poten…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The attacker provides an intranet address through the base url field configured in the Execute Flow node 
→ Bypass checkDenyList / resolveAndValidate in httpSecurity.ts (not called)
→ Causes the server to initiate an HTTP request to any internal network address, read cloud metadata, or detect internal network services&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1280&amp;#34; height=&amp;#34;860&amp;#34; alt=&amp;#34;9a52a74e6fe2fd78e4962d1d68057fc2&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/20df0006-9129-4886-8928-16d19a617c23&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Then initiate the call:&lt;/p&gt;
&lt;p&gt;```
POST /api/v1/prediction/d6739838-d3b3-43d9-86ff-911a3d757a7e HTTP/1.1
Host: 127.0.0.1:3000
Content-Type: application/json
Authorization: Bearer apikey
Content-Length: 17&lt;/p&gt;
&lt;p&gt;{&amp;#34;question&amp;#34;: &amp;#34;1&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;Server received a request:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1432&amp;#34; height=&amp;#34;172&amp;#34; alt=&amp;#34;f45c757fec408e13739db068252ff21b&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/d3dfe0f5-83ec-4c79-ab32-754382a68d5f&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;And there is an echo:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1280&amp;#34; height=&amp;#34;666&amp;#34; alt=&amp;#34;fa0caf0deb306cfeeea8fdf8941a287e&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/55a94d25-120b-4e9c-9517-46c2fc2b667f&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Fix:
Call secureFetch for verification&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This is a Server-Side Request Forgery (SSRF) vulnerability that may lead to the following risks: 
- Explore Internal Web Applications
- Access sensitive management interfaces
- Leak internal configuration, credentials, or confidential information&lt;/p&gt;
&lt;p&gt;This vulnerability significantly increases the risk of internal service enumeration and poten…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9hrv-gvrv-6gf2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1145 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1145</guid>
    </item>
  </channel>
</rss>
