CVE-2024-36420
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the /api/v1/openai-assistants-file endpoint in index.ts is vulnerable to arbitrary file read due to lack of sanitization of the fileName body parameter. No known patches for this issue are available.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/FlowiseAI/Flowise/blob/e93ce07851cdc0fcde12374f301b8070f2043687/packages/server/src/index.ts#L982, https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36420.json, https://nvd.nist.gov/vuln/detail/CVE-2024-36420, https://securitylab.github.com/advisories/GHSL-2023-232GHSL-2023-234Flowise/
