PT-2024-24158 · Flowiseai · Flowise

Maerifat Majeed

·

Published

2024-04-29

·

Updated

2026-05-31

·

CVE-2024-31621

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions FlowiseAI Inc Flowise versions 1.6.2 and before FlowiseAI Inc Flowise versions prior to 1.8.1
Description An issue in FlowiseAI Inc Flowise allows a remote attacker to execute arbitrary code via a crafted script sent to the /api/v1 component. The root cause is inadequate input validation. This issue is actively exploited in the wild.
Recommendations FlowiseAI Inc Flowise versions prior to 1.8.1 should be updated. FlowiseAI Inc Flowise version 1.6.2 and lower should be updated.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-31621
GHSA-6WP6-22X5-RR3W

Affected Products

Flowise