Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qm7-66jj-3q9w

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 6.8

Описание

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.

EPSS

Процентиль: 28%
0.00348
Низкий

8.3 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 6.8
nvd
3 дня назад

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.

EPSS

Процентиль: 28%
0.00348
Низкий

8.3 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-78