<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:29:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-348604</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348604</link>
      <description>EUVD-2026-348604</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348604</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69253</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69253</link>
      <description>&lt;p&gt;Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they inserted a user-controlled  baseURL  value straight into the JavaScript source, for example  const url = &amp;#34;${baseURL}/...&amp;#34;; . The only check on  baseURL  was  isValidURL , but a valid-looking URL can still contain characters that break out of a code string. An authenticated user could craft a  baseURL  that passed this check, closed the surrounding string, and injected their own JavaScript into the sandboxed script (code injection, CWE-94). The  vm2  sandbox runs in the same Node.js process as Flowise and exposes risky dependencies. As a result, the injected code could escape the sandbox and run arbitrary code on the Flowise server as the Flowise process user. Exploitation only requires an authenticated session. The issue is fixed in version 3.1.3, which passes the URL to the sandbox as data instead of inserting it into code and adds stricter URL validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they inserted a user-controlled  baseURL  value straight into the JavaScript source, for example  const url = &amp;#34;${baseURL}/...&amp;#34;; . The only check on  baseURL  was  isValidURL , but a valid-looking URL can still contain characters that break out of a code string. An authenticated user could craft a  baseURL  that passed this check, closed the surrounding string, and injected their own JavaScript into the sandboxed script (code injection, CWE-94). The  vm2  sandbox runs in the same Node.js process as Flowise and exposes risky dependencies. As a result, the injected code could escape the sandbox and run arbitrary code on the Flowise server as the Flowise process user. Exploitation only requires an authenticated session. The issue is fixed in version 3.1.3, which passes the URL to the sandbox as data instead of inserting it into code and adds stricter URL validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69253</guid>
    </item>
    <item>
      <title>GHSA-wg86-r78f-74mp — Flowise Sandbox Escape to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wg86-r78f-74mp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;=============================================================================
                                                            Security Advisory
                                                                       elttam&lt;/p&gt;
&lt;p&gt;Topic:          Flowise JavaScript Sandbox Escape&lt;/p&gt;
&lt;p&gt;Module:         FlowiseAI/Flowise, FlowiseAI/nodevm
Disclosed:      11-Apr-2026
Credits:        Luke Jahnke and Alex Brown
Affects:        `FlowiseAI/Flowise 3.1.1`, `FlowiseAI/nodevm  3.9.25`&lt;/p&gt;
&lt;p&gt;# I.   Background&lt;/p&gt;
&lt;p&gt;Flowise AI is an open-source, low-code platform for building AI applications—such as chatbots, workflows, and autonomous agents—through an intuitive drag-and-drop interface, minimising the need for extensive coding.&lt;/p&gt;
&lt;p&gt;The platform also enables execution of custom JavaScript within a sandboxed environment via the Custom Function Agent Flow node or Custom Tool. By default, this sandbox is powered by `patriksimek/vm2`, a fork of the `patriksimek/vm2` package.&lt;/p&gt;
&lt;p&gt;# II.  Problem Description&lt;/p&gt;
&lt;p&gt;**NOTE**: This vulnerability still impacts commit `dddfb3c90eec900d747790a439bd362a764039cd` (the latest commit on the main branch at the time of writing). The original report was incorrectly closed, due to a misunderstanding that the report was about the use of an outdated and vulnerable version of the `patriksimek/vm2` sandbox. The sandbox escape that this report documents is an issue with Flowise, and patching the `vm2` sandbox would not resolve it.&lt;/p&gt;
&lt;p&gt;The `patriksimek/vm2` sandbox executes JavaScript wit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;=============================================================================
                                                            Security Advisory
                                                                       elttam&lt;/p&gt;
&lt;p&gt;Topic:          Flowise JavaScript Sandbox Escape&lt;/p&gt;
&lt;p&gt;Module:         FlowiseAI/Flowise, FlowiseAI/nodevm
Disclosed:      11-Apr-2026
Credits:        Luke Jahnke and Alex Brown
Affects:        `FlowiseAI/Flowise 3.1.1`, `FlowiseAI/nodevm  3.9.25`&lt;/p&gt;
&lt;p&gt;# I.   Background&lt;/p&gt;
&lt;p&gt;Flowise AI is an open-source, low-code platform for building AI applications—such as chatbots, workflows, and autonomous agents—through an intuitive drag-and-drop interface, minimising the need for extensive coding.&lt;/p&gt;
&lt;p&gt;The platform also enables execution of custom JavaScript within a sandboxed environment via the Custom Function Agent Flow node or Custom Tool. By default, this sandbox is powered by `patriksimek/vm2`, a fork of the `patriksimek/vm2` package.&lt;/p&gt;
&lt;p&gt;# II.  Problem Description&lt;/p&gt;
&lt;p&gt;**NOTE**: This vulnerability still impacts commit `dddfb3c90eec900d747790a439bd362a764039cd` (the latest commit on the main branch at the time of writing). The original report was incorrectly closed, due to a misunderstanding that the report was about the use of an outdated and vulnerable version of the `patriksimek/vm2` sandbox. The sandbox escape that this report documents is an issue with Flowise, and patching the `vm2` sandbox would not resolve it.&lt;/p&gt;
&lt;p&gt;The `patriksimek/vm2` sandbox executes JavaScript wit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wg86-r78f-74mp</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</guid>
    </item>
  </channel>
</rss>
