Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities BSI Germany

[UPDATE] [kritisch] Flowise: Schwachstelle ermöglicht Codeausführung

A critical remote code execution vulnerability (CVSS 10.0) in the Flowise AI low-code platform allows an unauthenticated, remote attacker to execute arbitrary code. The vulnerability affects all open-source versions of Flowise prior to version 2.2.7-patch.1. A patch is available, and users must upgrade to Flowise version 2.2.7-patch.1 to remediate the issue.
Read Full Article →

[WID-SEC-2025-0569] Flowise: Schwachstelle ermöglicht Codeausführung CVSS Base Score 10.0 (kritisch) CVSS Temporal Score 9.0 (kritisch) Remoteangriff ja Datum 16.03.2025 Stand UPDATE 26.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Flowise ist eine Benutzeroberfläche zur Erstellung von LLMs (Large Language Model). Produkte 16.03.2025 Open Source Flowise <2.2.7-patch.1 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Flowise ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article