Executive brief
Flowise is a low-code platform for building AI applications. An authenticated attacker can inject and execute arbitrary code through the api/v1 endpoint, potentially compromising the integrity and confidentiality of the platform and any workflows running on it.
Technical details
This vulnerability is a code injection issue (CWE-94) in Flowise prior to v1.8.1 affecting the api/v1 component. An authenticated attacker can craft a malicious script and submit it via the api/v1 endpoint to execute arbitrary code on the server. The vulnerability requires authentication (PR:L per CVSS:3.1) and is network-reachable. The attacker gains code execution capabilities, potentially leading to full compromise of the Flowise instance. A fix was applied in v1.8.1 with regex checks added to the authentication middleware (commit e32b643).
Affected products
- FlowiseAI Flowise prior to 1.8.1
Timeline
- 2024-04-29: disclosed
- 2024-04-29: patched: Fix released in v1.8.1