CVE-2024-36420: Flowise Path Injection at /api/v1/openai-assistants-file
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the /api/v1/openai-assistants-file
endpoint in index.ts
is vulnerable to arbitrary file read due to lack of sanitization of the fileName
body parameter. No known patches for this issue are available.
References
Detect and mitigate CVE-2024-36420 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →