Skip to content
FlowiseGHSA-6wp6-22x5-rr3w

Flowise vulnerable to code injection via api/v1

High7.6CVE-2024-31621 · Published Apr 29, 2024 · updated Aug 2, 2024

An issue in FlowiseAI Inc Flowise prior to v1.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
< 1.8.11.8.1
Details and references

More Flowise advisories

All Flowise
Advisory
Flowise Cross-site Scripting in/api/v1/credentials/id
Medium6.1Aug 5, 2024
Flowise Cross-site Scripting in /api/v1/public-chatflows/id
Medium6.1Aug 5, 2024
Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id
Medium6.1Aug 5, 2024
Flowise Cross-site Scripting in api/v1/chatflows/id
Medium6.1Aug 5, 2024
Flowise Path Injection at /api/v1/openai-assistants-file
High7.5Aug 5, 2024
Flowise Cors Misconfiguration in packages/server/src/index.ts
High7.5Aug 5, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.