CVE-2024-36420 GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file
Discription
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the /api/v1/openai-assistants-file endpoint in index.ts is vulnerable to arbitrary file read due to lack of sanitization of the fileName body parameter. No known patches for this issue are…Read More
References
Back to Main