Product
critical
advisory
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 8 CVEs 2 IOCsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
Flowise +6
rce
injection
cve-2026-69263
python-injection
authentication-bypass
oauth
cve-2026-70478
web-vulnerability
+7
6r
11t
8c
2i
updated
critical
advisory
Flowise CSVAgent Authenticated Remote Code Execution
2 rules 1 TTPFlowise versions 3.0.13 and earlier are vulnerable to authenticated remote code execution due to missing sanitization in the CSVAgent component's customReadCSVFunc parameter, leading to arbitrary code injection and server compromise.
Flowise +1
code-injection
rce
2r
1t