PT-2024-26988 · Flowise · Flowise

Kevin Stubbings

·

Published

2024-07-01

·

Updated

2026-06-07

·

CVE-2024-36420

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise version 1.4.3
Description The issue concerns a lack of sanitization of the fileName body parameter in the "/api/v1/openai-assistants-file" endpoint, which is located in the index.ts file. This lack of sanitization leads to an arbitrary file read vulnerability. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For Flowise version 1.4.3, as a temporary workaround, consider restricting access to the "/api/v1/openai-assistants-file" endpoint until a patch is available. Avoid using the fileName parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-36420
GHSA-H997-3FXJ-P5J8

Affected Products

Flowise