Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91937

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.

EPSS

Процентиль: 20%
0.00277
Низкий

7.5 High

CVSS3

Дефекты

CWE-943

Связанные уязвимости

CVSS3: 7.5
github
3 дня назад

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.

EPSS

Процентиль: 20%
0.00277
Низкий

7.5 High

CVSS3

Дефекты

CWE-943