S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 25, 2026

CVE-2024-36420 Scanner

CVE-2024-36420 Scanner - Arbitrary File Read vulnerability in Flowise

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-36420
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are available.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Flowiseby FlowiseAI
<= 1.4.3
flowiseby flowiseai
0
Updated Aug 22, 2026View on NVD →
Detail

Flowise is a software platform created by the company Flowise AI, designed primarily for managing and deploying machine learning models and workflows. It is used by data scientists, engineers, and IT professionals across various industries to streamline AI integration into existing business processes. Flowise provides a user-friendly interface for configuring AI tasks and offers robust server-side capabilities to facilitate large-scale computations. Institutions ranging from tech startups to large enterprises utilize Flowise to enhance their operational efficiency through data-driven insights. The platform's capabilities extend to optimizing data flows, reducing time to deployment, and improving AI model accuracy. Given its server-side processing, Flowise requires strict security measures to protect sensitive data being processed.

The Arbitrary File Read vulnerability allows attackers to exploit a path traversal flaw in the software, specifically in the fileName parameter of the /api/v1/openai-assistants-file endpoint. This vulnerability exists in Flowise version 1.4.3 due to inadequate input validation in the code. An attacker can send a specially crafted request to the server to access files that should be off-limits. Once exploited, this flaw can potentially expose sensitive information stored on the server, compromising security. This vulnerability can be particularly dangerous since it does not require authentication and can be executed remotely.

Technical details reveal that the flaw lies in the way the fileName parameter is handled within the index.ts file of the affected Flowise version. The absence of proper sanitization allows traversal sequences in the input, effectively bypassing directory restrictions. Attackers may leverage this by choosing specific paths leading to sensitive system files. The vulnerability can be exploited by sending crafted POST requests to the server, aiming at the /api/v1/openai-assistants-file endpoint. Confirmatory responses will include parts of the file requested, revealing system information.

If exploited, this vulnerability could lead to severe data breaches, allowing attackers access to sensitive or confidential information on the server. This can include authentication credentials, user data, and system configuration files. Such exposure can lead to further exploitation, enabling unauthorized access and potentially causing irreparable damage to the service integrity. Besides, attackers can leverage this information for social engineering attacks on the entity owning or using the software. The aftermath of such a breach could include financial loss, reputational damage, and legal liabilities for mishandling data protection.

REFERENCES

Solution Advice
  • Implement input validation and sanitization on the fileName parameter to prevent path traversal attacks.
  • Monitor for updates and apply patches as soon as they are released by the vendor.
  • Restrict access to sensitive files on the server and enforce proper permission settings.
  • Regularly audit server logs to detect any unauthorized file access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.