PT-2024-24158 · Flowiseai · Flowise

·

CVE-2024-31621

·

Published

2024-04-29

·

Updated

2026-05-31

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions FlowiseAI Inc Flowise versions 1.6.2 and before FlowiseAI Inc Flowise versions prior to 1.8.1
Description An issue in FlowiseAI Inc Flowise allows a remote attacker to execute arbitrary code via a crafted script sent to the /api/v1 component. The root cause is inadequate input validation. This issue is actively exploited in the wild.
Recommendations FlowiseAI Inc Flowise versions prior to 1.8.1 should be updated. FlowiseAI Inc Flowise version 1.6.2 and lower should be updated.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31621
GHSA-6WP6-22X5-RR3W

Affected Products

Flowise