Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities BSI Germany

[UPDATE] [kritisch] Flowise: Schwachstelle ermöglicht Codeausführung

A critical vulnerability (CVSS 9.8) in the Flowise AI platform allows unauthenticated remote attackers to execute arbitrary code. The flaw affects Flowise open-source versions up to and including 2.2.4. A mitigation is available, but the article does not specify a fixed version number for the upgrade.
Read Full Article →

[WID-SEC-2025-0568] Flowise: Schwachstelle ermöglicht Codeausführung CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 9.4 (kritisch) Remoteangriff ja Datum 13.03.2025 Stand UPDATE 26.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Flowise ist eine Benutzeroberfläche zur Erstellung von LLMs (Large Language Model). Produkte 13.03.2025 Open Source Flowise <=2.2.4 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Flowise ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article