Junglewise Threat Intelligence

CVE-2024-36423: Flowise Cross-site Scripting in /api/v1/public-chatflows/id

CVE-2024-36423 · Severity: low · CVSS 3.1 · Published 2024-08-05

Technologies: flowise (npm). Vendors: npm.

Executive brief

Flowise is a drag-and-drop UI platform for building customized large language model workflows. A reflected cross-site scripting (XSS) vulnerability in the public chatflows API endpoint allows unauthenticated attackers to inject malicious JavaScript by crafting special URLs. Successful exploitation could enable credential theft, phishing attacks, session hijacking, or unauthorized file access from the affected server.

Technical details

This is a reflected cross-site scripting (CWE-79) vulnerability in the /api/v1/public-chatflows/id endpoint of Flowise versions up to and including 1.4.3. When an invalid chatflow ID is supplied, the ID value is reflected into a 404 error page served as text/html without proper encoding or sanitization, allowing arbitrary JavaScript injection. The vulnerability requires user interaction (clicking a malicious link) but no authentication in the default configuration. An attacker can craft URLs to execute arbitrary scripts in the victim's browser context, potentially stealing session tokens, sensitive data, or combining this with path injection to read arbitrary files from the server. As of the advisory publication date, no patch was available.

Affected products

  • Flowise AI Flowise up to 1.4.3

Timeline

  • 2024-08-05: disclosed
  • 2024-07-01: advisory: CVE published

References

Related threats