Výsledky hledání

výrobce: Flowise× v celém archivu zrušit filtry

4 karet z 4 položek CZ · EN/orig

1

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.

EPSS 0.01 CVSS 9.8 CVE-2026-70477 Flowise US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

1

Flowise: disponibili PoC per lo sfruttamento di nuove vulnerabilità

Disponibili Proof of Concept (PoC) relativi a 10 nuove vulnerabilità individuate in Flowise, piattaforma open source per la creazione di agenti AI, chatbot e workflow basati su modelli linguistici.

EPSS 0.01 CVE-2026-73483 CVE-2026-73484 CVE-2026-73485 CVE-2026-73486 CVE-2026-73487 CVE-2026-73488 CVE-2026-73601 CVE-2026-73602 CVE-2026-73603 CVE-2026-73604 Flowise IT

· CSIRT Itálie (ACN) · Flowise: disponibili PoC per lo sfruttamento di nuove vulnerabilità

2

ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-69256.

EPSS 0.01 CVSS 8.8 CVE-2026-69256 Flowise US

· Zero Day Initiative · ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability

ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-69264.

EPSS 0.01 CVSS 9.8 CVE-2026-69264 Flowise US

· Zero Day Initiative · ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability