Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration (unauthenticated), arbitrary origins may be able to make requests to Flowise, stealing information from the user. This CORS misconfiguration may be chained with the path injection to allow an attacker attackers without access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2510 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration (unauthenticated), arbitrary origins may be able to make requests to Flowise, stealing information from the user. This CORS misconfiguration may be chained with the path injection to allow an attacker attackers without access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available.
Github GHSA Github GHSA GHSA-66f2-xxgm-f6xp Flowise Cors Misconfiguration in packages/server/src/index.ts
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T03:37:05.196Z

Reserved: 2024-05-27T15:59:57.034Z

Link: CVE-2024-36421

cve-icon Vulnrichment

Updated: 2024-07-01T21:03:44.618Z

cve-icon NVD

Status : Modified

Published: 2024-07-01T16:15:04.623

Modified: 2024-11-21T09:22:08.813

Link: CVE-2024-36421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.