Junglewise Threat Intelligence

CVE-2024-37145: Flowise Cross-site Scripting in chatflows-streaming endpoint

CVE-2024-37145 · Severity: low · CVSS 3.1 · Published 2024-08-05

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is a visual interface for building customized AI chatbot flows. A reflected cross-site scripting (XSS) vulnerability in version 1.4.3 allows attackers to inject malicious JavaScript into user sessions by crafting specially designed URLs. An attacker can exploit this to steal user information, create fake popups, redirect users to malicious sites, or when chained with other vulnerabilities, read sensitive files from the server without authentication.

Technical details

The vulnerability is a reflected cross-site scripting (CWE-79) in the /api/v1/chatflows-streaming/id endpoint. When a chatflow ID is not found, the endpoint returns a 404 error page with type text/html that reflects the unvalidated chatflow ID parameter directly into the response, allowing arbitrary JavaScript injection. The vulnerability affects unauthenticated instances (default configuration) and has a network attack vector requiring only user interaction (clicking a malicious link). An attacker can craft a URL containing malicious JavaScript that executes in the victim's browser, potentially exfiltrating sensitive data or chaining the XSS with path injection vulnerabilities to read arbitrary files from the server. As of the advisory publication date (2024-08-05), no patches were available.

Affected products

  • FlowiseAI Flowise up to 1.4.3

Timeline

  • 2024-07-01: disclosed: NVD publication
  • 2024-08-05: advisory: GHSA advisory published

References

Related threats