FlowiseAI Flowise
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*
- 2.2.6
An arbitrary file upload vulnerability has been identified in FlowiseAI Flowise version 2.2.6. The issue resides in the attachments API endpoint, allowing unauthorized users to upload files potentially leading to further exploitation.
Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious files that the application might execute or serve.
A patch for this vulnerability is available. Instructions can be found in the repository's patch file.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.