2026-08-04
2026-08-04 19:16Z
HIGH

CVE-2026-70472 — Flowiseai Flowise: Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70472

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes req.query.credential straight to the service, and the service uses findOneBy({ id: credentialId } CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 285CWECWE 863VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 19:16Z
CRIT

CVE-2026-69703 — Atlas: Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69703

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDAtlasTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 19:16Z
CRIT

CVE-2026-49435 — Keysight: IxChariot Endpoint and associated products contain a stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49435

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDKeysightTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 19:16Z
CRIT

CVE-2026-0163 — In multiple functions of vpu_ioctl.c, there is a possible use after free due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0163

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 19:16Z
CRIT

CVE-2017-20242 — Keysight: IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20242

Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDKeysightTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 19:16Z
CRIT

CVE-2017-20241 — Keysight: IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20241

Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDKeysightTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 18:16Z
CRIT

CVE-2026-70470 — Flowiseai Flowise: JavaScript regex word boundaries are ASCII-only, while Python 3 NFKC-normalizes identifiers at parse time

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70470

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide js module interop. The validator gates pyodide.runPythonAsync in packages/components/nodes/agents/CSVAgent/CSVAgent.ts an CVSSv3.1 9.8 (CRITICAL) · EPSS 42th percentile

CWECWE 184VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-04
2026-08-04 18:16Z
CRIT

CVE-2026-69264 — Flowiseai Flowise: Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69264

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval and dynamic import, the attacker can break out of the Python string literal, hand a JavaScript string to js.eval, dynamically import Node built-in modules such as fs and child_process, and execute arbitr CVSSv3.1 9.8 (CRITICAL) · EPSS 46th percentile

CWECWE 94CWECWE 95VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 18:16Z
HIGH

CVE-2026-47623 — NVIDIA: Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47623

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. CVSSv3.1 8.2 (HIGH)

CWECWE 502VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 18:16Z
CRIT

CVE-2026-24254 — NVIDIA: Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24254

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDNvidiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 18:16Z
HIGH

CVE-2026-24253 — NVIDIA: Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24253

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 18:16Z
HIGH

CVE-2026-18830 — Amazon: Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18830

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. CVSSv3.1 8.1 (HIGH)

CWECWE 1287VNDAmazonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 17:17Z
CRIT

CVE-2026-69263 — Flowiseai Flowise: Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69263

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing CVSSv3.1 9.8 (CRITICAL) · EPSS 26th percentile

CWECWE 184VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 17:17Z
HIGH

CVE-2026-69262 — Flowiseai Flowise: Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69262

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHAT CVSSv3.1 8.1 (HIGH) · EPSS 25th percentile

CWECWE 863VNDFlowiseaiVNDFlowiseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 17:17Z
HIGH

CVE-2026-69259 — Flowiseai Flowise: Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additi

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69259

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write CVSSv3.1 8.8 (HIGH) · EPSS 29th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 17:17Z
CRIT

CVE-2026-69258 — Flowiseai Flowise: Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69258

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow exe CVSSv3.1 9.1 (CRITICAL) · EPSS 44th percentile

CWECWE 639CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 17:17Z
HIGH

CVE-2026-69257 — Flowiseai Flowise: Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69257

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a host CVSSv3.1 8.6 (HIGH) · EPSS 25th percentile

CWECWE 918CWECWE 1389VNDFlowiseaiVNDFlowiseTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-04
2026-08-04 17:17Z
HIGH

CVE-2026-69256 — Flowiseai Flowise: Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69256

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFu CVSSv3.1 8.8 (HIGH) · EPSS 33th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 17:17Z
HIGH

CVE-2026-69255 — Flowiseai Flowise: Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69255

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code blo CVSSv3.1 8.8 (HIGH) · EPSS 46th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 17:16Z
CRIT

CVE-2026-63456 — REST: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63456

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. CVSSv3.1 9.8 (CRITICAL)

VNDRestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 17:16Z
CRIT

CVE-2026-63455 — REST: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63455

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. CVSSv3.1 9.8 (CRITICAL)

VNDRestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 17:16Z
HIGH

CVE-2026-18787 — The manipulation of the argument args.id leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18787

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure. CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 17:16Z
HIGH

CVE-2026-15307 — Django: Writing a file to a location later imported by the application can result in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15307

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view CVSSv3.1 8.8 (HIGH)

CWECWE 918CWECWE 73VNDDjangoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 17:16Z
CRIT

CVE-2025-29296 — H3C: Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-29296

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected mod CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDH3cTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 16:16Z
HIGH

CVE-2026-69254 — Flowiseai Flowise: An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported flowise-components/dist/src/u

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69254

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported flowise-components/dist/src/utils.js, called executeJavaScriptCode() again with no CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score