Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.7epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
FlowiseAI · Flowisepublic PoCs found — 1
cve_referencegist.github.com/haidang-infosec/402db84bee7aca2f57bb109b31574649?utm_source=chatgpt.comunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.