VDB
KO
HIGH 7.5

GHSA-48x4-mx8f-gr4h

Flowise Unauthenticated Denial of Service (DoS) vulnerability

Details

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the `/api/v1/get-upload-file` api endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / flowise
Introduced in: 0

No fixed version published yet for flowise (npm). Pin to a known-safe version or switch to an alternative.

References