HIGH 7.6
GHSA-6wp6-22x5-rr3w
Flowise vulnerable to code injection via api/v1
Details
An issue in FlowiseAI Inc Flowise prior to v1.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-31621 [ADVISORY]
- https://github.com/FlowiseAI/Flowise/commit/e32b64344544312bf38b3e1fefe7b26c1776a426 [WEB]
- https://flowiseai.com [WEB]
- https://github.com/FlowiseAI/Flowise [PACKAGE]
- https://github.com/FlowiseAI/Flowise/blob/flowise%401.6.5/packages/server/src/index.ts#L143-L147 [WEB]
- https://www.exploit-db.com/exploits/52001 [WEB]