Miggo Logo

GHSA-7944-7c6r-55vv: FlowiseAI Pre-Auth Arbitrary Code Execution

9.1

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
Published
9/15/2025
Updated
9/15/2025
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
flowisenpm= 3.0.53.0.6

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

## Summ*ry *n *ut**nti**t** **min us*r o* ***lowis**I** **n *xploit t** **Sup***s* RP* *ilt*r** *ompon*nt to *x**ut* ***r*itr*ry s*rv*r-si** *o**** wit*out r*stri*tion. *y inj**tin* * m*li*ious p*ylo** into t** *ilt*r *xpr*ssion *i*l*, t** *tt**k*r

Reasoning

No *n*lysis *v*il**l*