VDB
KO
HIGH

GHSA-69jq-qr7w-j7qh

FlowiseAI Flowise arbitrary file upload vulnerability

Details

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / flowise
Introduced in: 0

No fixed version published yet for flowise (npm). Pin to a known-safe version or switch to an alternative.

References