PoC Index

CVE-2024-31621

HIGH 7.6EPSS 59.9%

An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

CVSS v4.0
7.2 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS v3.1
7.6 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CVSS v3.1
7.6 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
EPSS
59.87% chance of exploitation in the next 30 days, 99th percentile
Nuclei
high · CWE-94
Published
2024-04-29
Updated
2024-08-02

Nuclei templates (1)

ExploitDB entries (1)

References

Related