Junglewise Threat Intelligence

CVE-2024-36420: Flowise path injection in /api/v1/openai-assistants-file

CVE-2024-36420 · Severity: low · CVSS 3.1 · Published 2024-08-05

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is a drag-and-drop interface for building customized large language model workflows. An attacker can exploit an unsanitized API endpoint to read arbitrary files from the server, potentially accessing sensitive configuration files, credentials, or other private data without authentication.

Technical details

The /api/v1/openai-assistants-file endpoint in Flowise version 1.4.3 contains a path injection vulnerability (CWE-74) caused by insufficient sanitization of the fileName body parameter. An unauthenticated, network-accessible attacker can craft a malicious request with path traversal sequences (e.g., "../") to bypass directory restrictions and read arbitrary files from the server filesystem. The vulnerability allows confidentiality compromise without requiring authentication, user interaction, or system modification. No patches are currently available for this vulnerability.

Affected products

  • FlowiseAI Flowise through 1.4.3

Timeline

  • 2024-08-05: disclosed
  • 2024-07-01: other: CVE published by NVD

References

Related threats