Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47775
HistoryJun 27, 2024 - 6:50 a.m.

Code Injection

2024-06-2706:50:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
vulnerability
flowise
software
input validation
api
remote attacker
code injection

7.7 High

AI Score

Confidence

Low

flowise is vulnerable to Code Injection. The vulnerability is due to improper input validation in the api/v1 endpoint, allowing a remote attacker to execute arbitrary code via a crafted script.

CPENameOperatorVersion
flowisele1.8.0
flowisele1.8.0

7.7 High

AI Score

Confidence

Low