HIGH 7.6 npm
Flowise vulnerable to code injection via api/v1
GHSA-6wp6-22x5-rr3w · CVE-2024-31621
Published · Modified
Description
An issue in FlowiseAI Inc Flowise prior to v1.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-31621
- WEB https://github.com/FlowiseAI/Flowise/commit/e32b64344544312bf38b3e1fefe7b26c1776a426
- WEB https://flowiseai.com
- PACKAGE https://github.com/FlowiseAI/Flowise
- WEB https://github.com/FlowiseAI/Flowise/blob/flowise%401.6.5/packages/server/src/index.ts#L143-L147
- WEB https://www.exploit-db.com/exploits/52001
Ready to move
Start Securing
Free, no credit card | First findings in minutes