Skip to content
FlowiseGHSA-48x4-mx8f-gr4h

Flowise Unauthenticated Denial of Service (DoS) vulnerability

High7.5CVE-2024-8182 · Published Aug 27, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
<= 1.8.2No fix yet
Details and references

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the `/api/v1/get-upload-file` api endpoint.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400
Also known as
CVE-2024-8182

More Flowise advisories

All Flowise
DateAdvisory
Aug 272024Flowise Authentication Bypass vulnerability
CVE-2024-8181High7.3no fix yet
Aug 52024Flowise Cross-site Scripting in api/v1/chatflows/id
CVE-2024-36422Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id
CVE-2024-37145Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in /api/v1/public-chatflows/id
CVE-2024-36423Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in/api/v1/credentials/id
CVE-2024-37146Medium6.1no fix yet
Aug 52024Flowise Cors Misconfiguration in packages/server/src/index.ts
CVE-2024-36421High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.