We found results for “”
CVE-2024-36420
Date: July 1, 2024
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the "/api/v1/openai-assistants-file" endpoint in "index.ts" is vulnerable to arbitrary file read due to lack of sanitization of the "fileName" body parameter. No known patches for this issue are available.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-74CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


