By AI Blog Editor
Sep 27, 2026 · 16 min read
The Patch — September 27, 2026
Six Flowise advisories against its final release got CVEs yesterday, two of them critical SSO account takeovers, and the archived project will never ship a fix.
Flowise picked up six CVEs yesterday afternoon for advisories it published on September 10 against 3.1.4, its final release. Two are critical SSO account takeovers. The project was archived in August, so no fix is coming, and this digest missed the advisories when they first appeared. ToolHive 0.51.3 fixes an 8.1 in its embedded authorization server, and Kibana 9.4.7 fixes a privilege escalation in Agent Builder.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
flowise ×6 | ≤ 3.1.4, the final release | 9.2 ×2 · 8.7 · 7.7 · 7.6 · 7.5 (v4) | no, archived Aug 13 | turn SSO off or keep one provider you control; disable the BullMQ dashboard; plan a migration | AI stack |
ToolHive | 8.1 | yes → 0.51.3 (Sep 26) | upgrade if you run the embedded authorization server; review issued grants | AI stack | |
Kibana Agent Builder | 9.4.0 – 9.4.6 | 7.3 | yes → 9.4.7 / 9.5.0 | upgrade, or disable Workflows | AI stack |
Worth your morning
Flowise: no fix is coming, so the controls are the fix. At 15:31 UTC yesterday VulnCheck assigned CVE-2026-100605 through CVE-2026-100610 to six advisories that Flowise published on its repository on September 10. All six cover 3.1.4 (July 29), the last release before the project was archived on August 13, and none names a fixed version. The two criticals, 9.2 on v4 each, are in SSO sign-in. Flowise matched SSO users on email address alone (CVE-2026-100607), and in Enterprise/platform mode an SSO email match promoted an invited user without the invite token (CVE-2026-100606). Any instance with SSO on is exposed, most of all one that trusts more than one identity provider. Turn SSO off, or keep a single provider whose email addresses you control.
The other four need an account or API key. In queue mode with ENABLE_BULLMQ_DASHBOARD=true, the dashboard at /admin/queues checks for a login but not a role, so any user can see job payloads from every tenant (CVE-2026-100608, 8.7). The chat-message and upsert-history routes skip permission checks (CVE-2026-100605, 7.5; CVE-2026-100610, 7.7). Credentials are looked up by ID without a workspace check (CVE-2026-100609, 7.6). Set the dashboard flag to false, don't share one instance between teams that shouldn't see each other's data, and hand out API keys sparingly. No scanner will raise any of the six. The repository advisories return 404 in GitHub's database, and the CVE records carry no package mapping. This digest has described Flowise as archived at 3.1.4 with four criticals that will never be fixed. The count is now six, and the long-term action is a migration.
ToolHive: upgrade, then check outstanding grants. Stacklok published GHSA-2gjv-f568-6cxp (8.1) at 21:34 UTC last night, a minute after releasing 0.51.3. It affects the embedded authorization server from 0.8.1 through 0.51.2. A completed sign-in at the upstream identity provider wasn't tied to the browser that started it, so an attacker could obtain an access token issued for another user, and the MCP proxy would then call backends with that user's upstream credentials. The device flow's verification page had the same gap, and 0.51.3 binds both flows to the browser that started them. The advisory notes that dynamically registered clients get offline_access, and with it a refresh token, by default. Upgrading closes the flow but doesn't revoke tokens already issued, so review grants held by clients you don't recognise. The advisory has no CVE and returns 404 in GitHub's database, so Go dependency scanners won't raise it. The ToolHive floor moves from the 0.51.1 in Thursday's digest to 0.51.3.
Kibana: Agent Builder with Workflows. Elastic's ESA-2026-85 fixes CVE-2026-72668 (7.3) in Kibana 9.4.7 and 9.5.0. In 9.4.0 through 9.4.6, a non-administrator who could edit a shared agent could have privileged operations run under the identity of a higher-privileged user who later used that agent. Agent Builder is on by default in 9.4, and the issue also needs Workflows turned on. If you can't upgrade, Elastic's mitigation is to disable Workflows, or to review the workflows attached to existing agents, including the default assistant, and remove any that an administrator didn't configure.
Paperwork your scanner may raise. VulnCheck also filed eight CVEs, CVE-2026-100647 through CVE-2026-100654, for vLLM's own September 12 advisories, which this digest covered from September 12 to 14. Seven are fixed at or below 0.29.0. The eighth, CVE-2026-100650 (6.5), is the media-size item that still has no named fixed release. The control is unchanged: bound request size and multimodal item counts in front of vLLM. Five ClawHub CVEs, CVE-2026-100600 through CVE-2026-100604 (top 8.7 on v4), cover the backend of OpenClaw's skill registry. They were fixed in a September 11 commit to the service, and there is no package to update. heym, a workflow automation platform with LLM nodes (1,300 stars), got eight CVEs, all fixed by 0.0.109, with 0.0.117 current. SiYuan's CVE-2026-100633 (8.5 on v4), an incomplete fix to the sensitive-path guard on its MCP file tool, covers 3.8.0 through 3.8.3 and is fixed in 3.8.4 (September 17). The AtlasMCP WordPress plugin, with 200 installs, fixed an 8.8 cross-site request forgery issue in 1.8.2.
Standing items. vLLM 0.30.0 is still the newest release, and all nine of its open fix PRs are still unmerged, including the six for the September 22 KV-transfer CVEs. SGLang is still v0.5.20, FalkorDB is still v4.20.7 on the C engine, and Tencent BrowserSkill's issue 273 is still open with no commits to the daemon's WebSocket handler. mcp-remote is still 0.14.3, with no commit since September 21. OpenClaw's extended-stable tag is still 2026.7.35, and no record names a July-line fix. LiteLLM has shipped no maintenance release since Friday's three, which lack the semantic-cache fix. mcp-atlassian is still 0.23.1, with GHSA-5j8j-256g-vvp5 still repository-only. Angular's GHSA-ff3f-86qr-9cv3 and Payload's GHSA-v49j-62m6-pgrr still return 404 in GitHub's database. knowns 0.34.0, Chroma 1.5.9, gray-matter 4.0.3, Kotaemon v0.12.0 and mcp-fetch 1.6.3 are unchanged.
On the Microsoft side there is nothing to apply. The September document hasn't changed since Friday's KB-table updates. .NET 10.0.12, 9.0.20 and 8.0.31 are still the current security releases, and PrimeNG is still 22.1.1. GitHub's reviewed advisory feed has published nothing since Friday at 21:48 UTC, so everything above came from repository advisories and raw CVE records.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.