Impact
Flowise versions before 3.1.4 are vulnerable to a command injection flaw in Docker image build workflows. The flaw arises when workflow_dispatch inputs are interpolated directly into shell run blocks, allowing attackers who can write to the repository to inject shell metacharacters via fields such as tag_version and node_version. This injection permits arbitrary command execution, potentially leading to credential theft or other malicious activity.
Affected Systems
The vulnerability affects FlowiseAI’s Flowise product when deployed with Docker workflows and using any version earlier than 3.1.4. Users of the Flowise application who manage workflow_dispatch parameters in their GitHub Actions or similar automation are directly impacted.
Risk and Exploitability
With a CVSS score of 8.3, the flaw presents a serious risk, and although the EPSS score is less than 1%, the lack of a listing in CISA KEV suggests limited publicly known exploits yet the high severity warrants proactive mitigation. Attackers need repository write access to trigger the vulnerable workflow, a condition that can be satisfied by authenticated collaborators or breached credentials. Once the payload runs, the attacker can execute arbitrary commands, potentially exfiltrating AWS credentials and Docker Hub tokens. The attack vector is inferred to be through GitHub Actions or similar CI/CD pipelines that use Docker image build steps where the unchecked inputs are incorporated.
OpenCVE Enrichment