Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcg8-jx3g-5wm7

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.

EPSS

Процентиль: 20%
0.00277
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-943

Связанные уязвимости

CVSS3: 7.5
nvd
3 дня назад

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.

EPSS

Процентиль: 20%
0.00277
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-943