Headline
GHSA-h997-3fxj-p5j8: Flowise Path Injection at /api/v1/openai-assistants-file
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the /api/v1/openai-assistants-file
endpoint in index.ts
is vulnerable to arbitrary file read due to lack of sanitization of the fileName
body parameter. No known patches for this issue are available.
Flowise Path Injection at /api/v1/openai-assistants-file
High severity GitHub Reviewed Published Aug 5, 2024 to the GitHub Advisory Database • Updated Aug 5, 2024