Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with r…
Medium CVSS 6.8
Summary
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jrcq-qjw5-xx5q
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-script-injection-via-docker-workflows
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jrcq-qjw5-xx5q
Timeline
- nvd_ingest NVD