FlowiseGHSA-h997-3fxj-p5j8
Flowise Path Injection at /api/v1/openai-assistants-file
High7.5CVE-2024-36420 · Published Aug 5, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| flowise npm | <= 1.4.3 | No fix yet |
Details and references
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are available.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-74
- Also known as
- CVE-2024-36420
More Flowise advisories
All Flowise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 52024 | Flowise Cors Misconfiguration in packages/server/src/index.ts CVE-2024-36421High7.5no fix yet | High7.5 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in api/v1/chatflows/id CVE-2024-36422Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id CVE-2024-37145Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in /api/v1/public-chatflows/id CVE-2024-36423Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in/api/v1/credentials/id CVE-2024-37146Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 272024 | Flowise Authentication Bypass vulnerability CVE-2024-8181High7.3no fix yet | High7.3 | No fix yet |