icon

We found results for “

CVE-2024-36420

Date: July 1, 2024

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the "/api/v1/openai-assistants-file" endpoint in "index.ts" is vulnerable to arbitrary file read due to lack of sanitization of the "fileName" body parameter. No known patches for this issue are available.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-74

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us