CNNVD-202508-1511 Information

CNNVD ID

CNNVD-202508-1511

CVE-2025-8943

  • CNNVD Published: 2025-08-14

Description (Chinese)

Flowise是FlowiseAI开源的一个用于轻松构建 LLM 应用程序的工具。 Flowise 3.0.1之前版本存在安全漏洞,该漏洞源于默认安装缺乏身份验证和基于角色的访问控制,可能导致执行未沙箱化的OS命令。

Description (English)

Flowise is an open-source tool for easy construction of LLM applications. There was a security loophole in the previous version of Flowise 3.1, which resulted from the default installation of lack of identification and role-based access controls, which could lead to the implementation of unsandled OS orders.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

Flute

Published

2025-08-14

Last Modified

2026-02-24

References

https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/ https://nvd.nist.gov/vuln/detail/CVE-2025-8943

Patch

https://flowiseai.com/

Share on: