Skip to content
FlowiseGHSA-2q4w-x8h2-2fvh

Flowise Authentication Bypass vulnerability

High7.3CVE-2024-8181 · Published Aug 27, 2024 · updated Sep 4, 2024

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
<= 1.8.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-285, CWE-287
Also known as
CVE-2024-8181

More Flowise advisories

All Flowise
Advisory
Flowise Unauthenticated Denial of Service (DoS) vulnerability
High7.5Aug 27, 2024
Flowise Cross-site Scripting in api/v1/chatflows/id
Medium6.1Aug 5, 2024
Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id
Medium6.1Aug 5, 2024
Flowise Cross-site Scripting in /api/v1/public-chatflows/id
Medium6.1Aug 5, 2024
Flowise Cross-site Scripting in/api/v1/credentials/id
Medium6.1Aug 5, 2024
Flowise Cors Misconfiguration in packages/server/src/index.ts
High7.5Aug 5, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.