PoC Archive PoC Archive

tag

Flowise

Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CVE-2026-56271webCRITICAL 9.8Patched2026-07-12Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528) EPSS 87%
CVE-2025-59528 web Patched
CVE-2025-59528webCRITICAL 10Patched2026-07-06Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824 EPSS 36%
CVE-2026-30824 web Patched
CVE-2026-30824webCRITICAL 9.8Patched2026-07-05Flowise Custom MCP Environment Variable Case Bypass
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03