CWE-95

CWE-95 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-95, highest CVSS first.

  1. HIGH 8.8CVE-2026-67195

    Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied inpu

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-69264public PoC

    Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-69253public PoC

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that co

    AI risk analysis on Exploit-DB.ai →