Flowise servers used to build AI agents and automated workflows are facing six newly disclosed remote code execution flaws. The weaknesses could allow authenticated attackers to run commands on the underlying server, putting data, credentials, and connected systems at risk. The attack paths involve several Flowise components, including CSV processing, custom JavaScript functions, MCP configurations, database nodes, and record-management features. The findings add to concerns raised by previous Flowise injection exploitation, where exposed AI workflow servers became attractive targets for attackers. Researchers at Elttam identified the issues while reviewing Flowise versions 3.1.1 and 3.1.2. Elttam said in a...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!