{"id":"CVE-2026-96431","published":"2026-09-29T09:17:11.183","lastModified":"2026-09-29T21:33:56.530","description":"Unrestricted Upload of File with Dangerous Type in the\n/WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version\nbefore 2023/03/24 allows remote authenticated users to execute arbitrary\nsystem commands via a malicious file.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://zuso.ai/cve-advisory/advisory","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}