Skip to content
FlowiseGHSA-h997-3fxj-p5j8

Flowise Path Injection at /api/v1/openai-assistants-file

High7.5CVE-2024-36420 · Published Aug 5, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
<= 1.4.3No fix yet
Details and references

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are available.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-74
Also known as
CVE-2024-36420

More Flowise advisories

All Flowise
DateAdvisory
Aug 52024Flowise Cors Misconfiguration in packages/server/src/index.ts
CVE-2024-36421High7.5no fix yet
Aug 52024Flowise Cross-site Scripting in api/v1/chatflows/id
CVE-2024-36422Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id
CVE-2024-37145Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in /api/v1/public-chatflows/id
CVE-2024-36423Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in/api/v1/credentials/id
CVE-2024-37146Medium6.1no fix yet
Aug 272024Flowise Authentication Bypass vulnerability
CVE-2024-8181High7.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.