<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:54:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-348626</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348626</link>
      <description>EUVD-2026-348626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348626</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69258</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69258</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69258</guid>
    </item>
    <item>
      <title>GHSA-6vh2-wg4h-4vwj — Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Predicti…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6vh2-wg4h-4vwj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditionally spread into the internal `flowConfig` and `flowData` objects at two locations in the codebase **without checking** `apiOverrideStatus`. This allows an unauthenticated attacker to inject arbitrary properties into the flow execution context of any public chatflow, enabling session hijacking, cross-session data pollution, chat history manipulation, and injection of attacker-controlled values into `$flow.*` template variables consumed by flow nodes.&lt;/p&gt;
&lt;p&gt;This is distinct from the previously reported `overrideConfig` vulnerability (GHSA-5cph-wvm9-45gj), which addressed overrideConfig&amp;#39;s ability to modify **node input parameters** via `replaceInputsWithConfig()`. That function is properly gated behind `apiOverrideStatus`. The vulnerability reported here is in two **separate, ungated spread operations** that were not addressed by the GHSA-5cph fix.&lt;/p&gt;
&lt;p&gt;#### Root Cause&lt;/p&gt;
&lt;p&gt;In `packages/server/src/utils/buildChatflow.ts` at lines 557–564, the `incomingInput.overrideConfig` object is spread directly into `flowConfig` with no gating:&lt;/p&gt;
&lt;p&gt;```typescript
// File: packages/server/src/utils/buildChatflow.ts, lines 557-564
const flowConfig: IFlowConfig = {
    chatflowid,
    chatflowId: chatflow.id,
    chatId,
    sessionId,
    chatHistory,
    apiMessageId,
    ...incomingInput.overrideConfig  // &amp;lt;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditionally spread into the internal `flowConfig` and `flowData` objects at two locations in the codebase **without checking** `apiOverrideStatus`. This allows an unauthenticated attacker to inject arbitrary properties into the flow execution context of any public chatflow, enabling session hijacking, cross-session data pollution, chat history manipulation, and injection of attacker-controlled values into `$flow.*` template variables consumed by flow nodes.&lt;/p&gt;
&lt;p&gt;This is distinct from the previously reported `overrideConfig` vulnerability (GHSA-5cph-wvm9-45gj), which addressed overrideConfig&amp;#39;s ability to modify **node input parameters** via `replaceInputsWithConfig()`. That function is properly gated behind `apiOverrideStatus`. The vulnerability reported here is in two **separate, ungated spread operations** that were not addressed by the GHSA-5cph fix.&lt;/p&gt;
&lt;p&gt;#### Root Cause&lt;/p&gt;
&lt;p&gt;In `packages/server/src/utils/buildChatflow.ts` at lines 557–564, the `incomingInput.overrideConfig` object is spread directly into `flowConfig` with no gating:&lt;/p&gt;
&lt;p&gt;```typescript
// File: packages/server/src/utils/buildChatflow.ts, lines 557-564
const flowConfig: IFlowConfig = {
    chatflowid,
    chatflowId: chatflow.id,
    chatId,
    sessionId,
    chatHistory,
    apiMessageId,
    ...incomingInput.overrideConfig  // &amp;lt;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6vh2-wg4h-4vwj</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</guid>
    </item>
  </channel>
</rss>
