FlowiseAI / Flowise

Drag & drop UI to build your customized LLM flow
https://flowiseai.com
Apache License 2.0
31.25k stars 16.27k forks source link

[BUG] Request for confirmation of security reports. #3421

Open LIFE-team2024 opened 1 week ago

LIFE-team2024 commented 1 week ago

I reported four security issues through the Private Vulnerability Reporting (PVR), but I have not received a response yet. Could you please check the reports?

You can check the reports using the following links:

https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-xc96-r4g6-76gf https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-hv5w-qqvm-8hf7 https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c46v-5vvx-9qxv https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-594m-pqg6-f2gc

Thank you.

severfire commented 1 week ago

hmmm, links give 404 errors :-/ maybe they are not public.

LIFE-team2024 commented 1 week ago

hmmm, links give 404 errors :-/ maybe they are not public.

I think only the owner of FlowiseAI and the bug reporter can access this report, and that might be why.

HenryHengZJ commented 1 day ago

we received them, and are working on to fix the issues!