CWE-184

CWE-184 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-184, highest CVSS first.

  1. HIGH 8.6CVE-2026-71259public PoC

    ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_componen

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-70470public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbit

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-69263public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD

    AI risk analysis on Exploit-DB.ai →