Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91936

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.

EPSS

Процентиль: 28%
0.00348
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 6.8
github
3 дня назад

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.

EPSS

Процентиль: 28%
0.00348
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-78