GHSA-3g4j-r53p-22wx

Suggest an improvement
Source
https://github.com/advisories/GHSA-3g4j-r53p-22wx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-3g4j-r53p-22wx/GHSA-3g4j-r53p-22wx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3g4j-r53p-22wx
Withdrawn
2025-10-17T20:22:08Z
Published
2025-10-17T18:31:09Z
Modified
2025-10-17T20:22:08Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7944-7c6r-55vv. This link is maintained to preserve external references.

Original Description

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

Database specific
{
    "cwe_ids":  [
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-17T20:22:08Z",
    "nvd_published_at":  "2025-10-17T18:15:37Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / flowise

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.5
Fixed
3.0.6

Affected versions

3.*
3.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-3g4j-r53p-22wx/GHSA-3g4j-r53p-22wx.json"