GHSA-8vvx-qvq9-5948: Flowise allows arbitrary file write to RCE
An attacker could write files with arbitrary content to the filesystem via the /api/v1/document-store/loader/process
API.
An attacker can reach RCE(Remote Code Execution) via file writing.
References
Detect and mitigate GHSA-8vvx-qvq9-5948 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →