FlowiseGHSA-6wp6-22x5-rr3w
Flowise vulnerable to code injection via api/v1
High7.6CVE-2024-31621 · Published Apr 29, 2024 · updated Aug 2, 2024
An issue in FlowiseAI Inc Flowise prior to v1.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| flowise npm | < 1.8.1 | 1.8.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2024-31621
More Flowise advisories
All Flowise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 52024 | Flowise Cross-site Scripting in/api/v1/credentials/id | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in /api/v1/public-chatflows/id | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in api/v1/chatflows/id | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Path Injection at /api/v1/openai-assistants-file | High7.5 | No fix yet |
| Aug 52024 | Flowise Cors Misconfiguration in packages/server/src/index.ts | High7.5 | No fix yet |