CWE-184
CWE-184 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-184, highest CVSS first.
- HIGH 8.6CVE-2026-71259public PoC
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_componen…
- UNSCOREDCVE-2026-70470public PoC
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbit…
- UNSCOREDCVE-2026-69263public PoC
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD…