<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:40:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-348586</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348586</link>
      <description>EUVD-2026-348586</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348586</guid>
    </item>
    <item>
      <title>fkie_cve-2026-70474</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-70474</link>
      <description>&lt;p&gt;Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/&amp;lt;VICTIM_CREDENTIAL_UUID&amp;gt;, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&amp;amp;state=&amp;lt;VICTIM_CREDENTIAL_UUID&amp;gt;, and /api/v1/oauth2-credential/refresh/&amp;lt;VICTIM_CREDENTIAL_UUID&amp;gt;. This issue is fixed in version 3.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/&amp;lt;VICTIM_CREDENTIAL_UUID&amp;gt;, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&amp;amp;state=&amp;lt;VICTIM_CREDENTIAL_UUID&amp;gt;, and /api/v1/oauth2-credential/refresh/&amp;lt;VICTIM_CREDENTIAL_UUID&amp;gt;. This issue is fixed in version 3.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-70474</guid>
    </item>
    <item>
      <title>GHSA-wch5-xp77-fxg4 — Flowise: Cross-Workspace OAuth2 Credential Metadata Leak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wch5-xp77-fxg4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three OAuth2 credential endpoints look up credentials by `id` alone with no `workspaceId` filter. Two of these endpoints (`callback`, `refresh`) are whitelisted from all authentication. This allows:&lt;/p&gt;
&lt;p&gt;1. **Cross-workspace credential access** — Any authenticated user can initiate OAuth2 flows against credentials belonging to other workspaces.
2. **Unauthenticated token injection** — An unauthenticated attacker can forge OAuth2 callbacks to overwrite tokens in any credential.
3. **Unauthenticated token refresh** — An unauthenticated attacker can refresh tokens for any credential.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;### Vulnerable code: no workspace scoping&lt;/p&gt;
&lt;p&gt;All three OAuth2 handlers query the `Credential` table by `id` only:&lt;/p&gt;
&lt;p&gt;**`packages/server/src/routes/oauth2/index.ts:80-82`** (authorize)
```typescript
const credential = await credentialRepository.findOneBy({
    id: credentialId
    // Missing: workspaceId filter
})
```&lt;/p&gt;
&lt;p&gt;**`packages/server/src/routes/oauth2/index.ts:183-185`** (callback)
```typescript
const credential = await credentialRepository.findOneBy({
    id: state as string
    // Missing: workspaceId filter
})
```&lt;/p&gt;
&lt;p&gt;**`packages/server/src/routes/oauth2/index.ts:314-316`** (refresh)
```typescript
const credential = await credentialRepository.findOneBy({
    id: credentialId
    // Missing: workspaceId filter
})
```&lt;/p&gt;
&lt;p&gt;### Correct pattern (same codebase)&lt;/p&gt;
&lt;p&gt;The standard credential service correctly enforces workspace isolation:&lt;/p&gt;
&lt;p&gt;**`packages/server/src/services/credentials/in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three OAuth2 credential endpoints look up credentials by `id` alone with no `workspaceId` filter. Two of these endpoints (`callback`, `refresh`) are whitelisted from all authentication. This allows:&lt;/p&gt;
&lt;p&gt;1. **Cross-workspace credential access** — Any authenticated user can initiate OAuth2 flows against credentials belonging to other workspaces.
2. **Unauthenticated token injection** — An unauthenticated attacker can forge OAuth2 callbacks to overwrite tokens in any credential.
3. **Unauthenticated token refresh** — An unauthenticated attacker can refresh tokens for any credential.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;### Vulnerable code: no workspace scoping&lt;/p&gt;
&lt;p&gt;All three OAuth2 handlers query the `Credential` table by `id` only:&lt;/p&gt;
&lt;p&gt;**`packages/server/src/routes/oauth2/index.ts:80-82`** (authorize)
```typescript
const credential = await credentialRepository.findOneBy({
    id: credentialId
    // Missing: workspaceId filter
})
```&lt;/p&gt;
&lt;p&gt;**`packages/server/src/routes/oauth2/index.ts:183-185`** (callback)
```typescript
const credential = await credentialRepository.findOneBy({
    id: state as string
    // Missing: workspaceId filter
})
```&lt;/p&gt;
&lt;p&gt;**`packages/server/src/routes/oauth2/index.ts:314-316`** (refresh)
```typescript
const credential = await credentialRepository.findOneBy({
    id: credentialId
    // Missing: workspaceId filter
})
```&lt;/p&gt;
&lt;p&gt;### Correct pattern (same codebase)&lt;/p&gt;
&lt;p&gt;The standard credential service correctly enforces workspace isolation:&lt;/p&gt;
&lt;p&gt;**`packages/server/src/services/credentials/in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wch5-xp77-fxg4</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</guid>
    </item>
  </channel>
</rss>
