GHSA-h42x-xx2q-6v6g: Flowise Pre-auth Arbitrary File Upload
An unauthorized attacker can leverage the allow-listed route /api/v1/attachments
to upload arbitrary files when the storageType
is set to local (default).
References
Detect and mitigate GHSA-h42x-xx2q-6v6g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →