HIGH 7.5
GHSA-48x4-mx8f-gr4h
Flowise Unauthenticated Denial of Service (DoS) vulnerability
Details
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the `/api/v1/get-upload-file` api endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / flowise
Introduced in:
0 No fixed version published yet for flowise (npm). Pin to a known-safe version or switch to an alternative.