Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2024-58351
9.3CRITICAL
What is CVE-2024-58351?
Flowise prior to version 2.1.4 is susceptible to a vulnerability where an attacker can inject malicious configurations into the Chainflow during runtime through the overrideConfig option. This setting is enabled by default for both frontend integration and backend Prediction API, lacking a proper allow-list for safe variables. Exploitation of this flaw can lead to severe consequences, including remote code execution, denial of service from server crashes, server-side request forgery, prompt injection, and the potential exposure of server variables and sensitive data. Attacks are confined to the affected server and do not persist across different users.
Affected Version(s)
Flowise 0 < 2.1.4
Flowise 2.1.4
