- CVSS
- HIGH · 7.5v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Published
- 2024-07-01
- Weakness
- CWE-74, CWE-74
- Source
- nvd.nist.gov/vuln/detail/CVE-2024-36420
Description
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the /api/v1/openai-assistants-file endpoint in index.ts is vulnerable to arbitrary file read due to lack of sanitization of the fileName body parameter. No known patches for this issue are available.
References
- https://github.com/FlowiseAI/Flowise/blob/e93ce07851cdc0fcde12374f301b8070f2043687/packages/server/src/index.ts#L982
- https://securitylab.github.com/advisories/GHSL-2023-232_GHSL-2023-234_Flowise/
- https://github.com/FlowiseAI/Flowise/blob/e93ce07851cdc0fcde12374f301b8070f2043687/packages/server/src/index.ts#L982
- https://securitylab.github.com/advisories/GHSL-2023-232_GHSL-2023-234_Flowise/
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2024-36420 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.