3.0.3
2 years ago
5 days ago
Known vulnerabilities in the flowise package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
flowise is a Flowiseai Server Affected versions of this package are vulnerable to SQL Injection: Hibernate via the How to fix SQL Injection: Hibernate? Upgrade | <2.2.8 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Arbitrary Code Injection via the Note: The writing functions How to fix Arbitrary Code Injection? Upgrade | <2.1.0 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Arbitrary File Upload through the Note: This is only exploitable if the server configuration allows file uploads without proper validation or sanitization. How to fix Arbitrary File Upload? Upgrade | <2.2.7-patch.1 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to External Control of System or Configuration Setting via the How to fix External Control of System or Configuration Setting? Upgrade | <2.1.4 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the creation of a chatflow. An attacker can bypass input filters by providing a snippet without an event handler as input to a conversation, like How to fix Cross-site Scripting (XSS)? Upgrade | <2.1.1 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Uncontrolled Resource Consumption through the How to fix Uncontrolled Resource Consumption? There is no fixed version for | * |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Improper Authentication via the API endpoint authentication process. An attacker can gain unauthorized administrative access and manipulate restricted functionalities by bypassing the authentication mechanism. How to fix Improper Authentication? Upgrade | <2.0.6 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? There is no fixed version for | * |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the How to fix Cross-site Scripting (XSS)? There is no fixed version for | * |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? There is no fixed version for | * |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? There is no fixed version for | * |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Path Traversal due to improper sanitization of the How to fix Path Traversal? There is no fixed version for | * |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Origin Validation Error due to the use of the How to fix Origin Validation Error? Upgrade | <1.4.12 |
flowise is a Flowiseai Server Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection') due to improper input validation in the How to fix Improper Control of Generation of Code ('Code Injection')? Upgrade | <2.0.6 |