VDB
KO
HIGH 7.6

GHSA-6wp6-22x5-rr3w

Flowise vulnerable to code injection via api/v1

Details

An issue in FlowiseAI Inc Flowise prior to v1.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / flowise
Introduced in: 0 Fixed in: 1.8.1
Fix npm install flowise@1.8.1

References