Junglewise Threat Intelligence

CVE-2024-31621: Flowise code injection in api/v1

CVE-2024-31621 · Severity: low · CVSS 3.1 · Published 2024-04-29

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is a low-code platform for building AI applications. An authenticated attacker can inject and execute arbitrary code through the api/v1 endpoint, potentially compromising the integrity and confidentiality of the platform and any workflows running on it.

Technical details

This vulnerability is a code injection issue (CWE-94) in Flowise prior to v1.8.1 affecting the api/v1 component. An authenticated attacker can craft a malicious script and submit it via the api/v1 endpoint to execute arbitrary code on the server. The vulnerability requires authentication (PR:L per CVSS:3.1) and is network-reachable. The attacker gains code execution capabilities, potentially leading to full compromise of the Flowise instance. A fix was applied in v1.8.1 with regex checks added to the authentication middleware (commit e32b643).

Affected products

  • FlowiseAI Flowise prior to 1.8.1

Timeline

  • 2024-04-29: disclosed
  • 2024-04-29: patched: Fix released in v1.8.1

References

Related threats