<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:58:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-344159</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344159</link>
      <description>EUVD-2026-344159</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344159</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69263</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69263</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install and execute the named package when a Custom MCP server launched. This issue is fixed in version 3.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install and execute the named package when a Custom MCP server launched. This issue is fixed in version 3.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69263</guid>
    </item>
    <item>
      <title>GHSA-xc48-889x-5qmw — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xc48-889x-5qmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The mitigation shipped for CVE-2025-8943 blocks the `-y` and `--yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies only four variable names by exact string match, and `npm` reads its configuration directly from `npm_config_*` environment variables. Setting `npm_config_yes=true` reproduces the `--yes` behaviour the flag filter is meant to prevent, so `npx` auto-installs and executes the named package. The mitigation is fully bypassed.&lt;/p&gt;
&lt;p&gt;This works with the MCP security check enabled (`CUSTOM_MCP_SECURITY_CHECK=true`). On a default Flowise deployment, which ships with no authentication, the result is unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;The patch treats this as a flag-filtering problem, but the behaviour gated by `--yes` is also reachable through `npm`&amp;#39;s environment-based configuration. The same is true for the other permitted interpreters, `node` and `python3`. A denylist of variable names cannot enumerate every environment variable that alters execution, so the control is incomplete by construction. The fix is to allowlist (or strip) the environment before it reaches the child process, not to extend the denylist.&lt;/p&gt;
&lt;p&gt;## Affected version&lt;/p&gt;
&lt;p&gt;Flowise 3.1.1, current as of 2026-03-29.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Validation happens in `packages/components/nodes/tools/MCP/core.ts`. Two functions run in sequence before any MCP server launches: `validateCommandFlags` and `valida…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The mitigation shipped for CVE-2025-8943 blocks the `-y` and `--yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies only four variable names by exact string match, and `npm` reads its configuration directly from `npm_config_*` environment variables. Setting `npm_config_yes=true` reproduces the `--yes` behaviour the flag filter is meant to prevent, so `npx` auto-installs and executes the named package. The mitigation is fully bypassed.&lt;/p&gt;
&lt;p&gt;This works with the MCP security check enabled (`CUSTOM_MCP_SECURITY_CHECK=true`). On a default Flowise deployment, which ships with no authentication, the result is unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;The patch treats this as a flag-filtering problem, but the behaviour gated by `--yes` is also reachable through `npm`&amp;#39;s environment-based configuration. The same is true for the other permitted interpreters, `node` and `python3`. A denylist of variable names cannot enumerate every environment variable that alters execution, so the control is incomplete by construction. The fix is to allowlist (or strip) the environment before it reaches the child process, not to extend the denylist.&lt;/p&gt;
&lt;p&gt;## Affected version&lt;/p&gt;
&lt;p&gt;Flowise 3.1.1, current as of 2026-03-29.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Validation happens in `packages/components/nodes/tools/MCP/core.ts`. Two functions run in sequence before any MCP server launches: `validateCommandFlags` and `valida…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xc48-889x-5qmw</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</guid>
    </item>
  </channel>
</rss>
