ZeroHour

CVE-2026-30822

PoC
CVSS 3.0
7.7 high
EPSS
13%p96
Published
()
Modified
Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.

Vendors
flowiseai
Products
flowise
Weakness
CWE-915
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.