Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. flowise
  4. ›
  5. GHSA-99pg-hqvx-r4gf

GHSA-99pg-hqvx-r4gf: Flowise has an Arbitrary File Read

September 15, 2025

An arbitrary file read vulnerability in the chatId parameter supplied to both the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints allows unauthenticated users to read unintended files on the local filesystem. In the default Flowise configuration this allows reading of the local sqlite db and subsequent compromise of all database content.

References

  • github.com/FlowiseAI/Flowise
  • github.com/FlowiseAI/Flowise/security/advisories/GHSA-99pg-hqvx-r4gf
  • github.com/advisories/GHSA-99pg-hqvx-r4gf

Code Behaviors & Features

Detect and mitigate GHSA-99pg-hqvx-r4gf with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.0.5 before 3.0.6, version 3.0.5

Fixed versions

  • 3.0.6

Solution

Upgrade to version 3.0.6 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Learn more about CVSS

Source file

npm/flowise/GHSA-99pg-hqvx-r4gf.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 08 Oct 2025 00:20:20 +0000.