← Vulnerability feed

Vulnerability record · CVE-2024-8181 · published 27 August 2024

CVE-2024-8181: Flowise authentication bypass allows admin API access

Flowiseai · Flowise

Flowise version 1.8.2 contains an improper authentication flaw (CWE-287) that lets a remote, unauthenticated attacker reach API endpoints with administrator privileges. Because the affected endpoints expose restricted functionality, the flaw undermines the product's access control boundary and matters to any deployment reachable from an untrusted network.

8.1 CVSS 3.1 High EPSS 45% · top 1.3% CWE-287 · Improper authentication
8.1CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.1 with no authentication required and a very high EPSS percentile, though the need for user interaction and absence of confirmed exploitation keep it below critical.

What it is

Flowise version 1.8.2 contains an improper authentication flaw (CWE-287) that lets a remote, unauthenticated attacker reach API endpoints with administrator privileges. Because the affected endpoints expose restricted functionality, the flaw undermines the product's access control boundary and matters to any deployment reachable from an untrusted network.

Impact

An attacker gains administrator-level access to restricted API functionality without valid credentials. That access can be used to read or modify data and configuration exposed through those endpoints.

Attack surface

Reached over the network via the Flowise API (CVSS vector AV:N/AC:L/PR:N/UI:R). No authentication is required, but the vector indicates user interaction is needed, so exploitation likely depends on a victim triggering or visiting something.

Exploitation

No CISA KEV listing and no ransomware associations are recorded. EPSS is high at 0.4505 (98.7th percentile), indicating elevated predicted exploitation activity, but the record contains no public exploit or in-the-wild confirmation.

What to do

  • Upgrade Flowise from version 1.8.2 to a fixed release as soon as the vendor provides one; verify the fix against the vendor advisory.
  • Restrict network access to Flowise API endpoints to trusted networks or authenticated reverse proxies until patching is complete.
  • Enforce authentication and authorization at a fronting proxy or gateway so unauthenticated requests cannot reach the Flowise API directly.
  • Audit Flowise administrator accounts and API tokens for unauthorized changes or additions.
  • Monitor vendor and Tenable advisories for updated affected-version and patch information.

Detection

  • Review Flowise API access logs for requests to administrative endpoints from unauthenticated or unexpected source IPs.
  • Alert on successful admin-level API calls that lack a corresponding authenticated session or valid token.
  • Baseline normal Flowise API traffic and flag new or anomalous endpoint access patterns.
  • Correlate Flowise logs with proxy logs to identify requests that bypassed expected authentication controls.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8181 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-71338Flowiseai flowise vulnerabilityFlowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outsid…EPSS 1.2%10.0CVE-2025-59528Flowise CustomMCP node code injection enables remote code executionFlowise 3.0.5 passes user-supplied mcpServerConfig input directly into the JavaScript Function() constructor inside convertToValidJSONString, with no…EPSS 86%analysed9.9CVE-2026-40933Flowiseai flowise os command injection vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…EPSS 1.3%9.9CVE-2025-61913Flowiseai flowise path traversal vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…EPSS 13%9.8CVE-2026-52098Flowiseai flowise code injection vulnerabilityAn issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpointEPSS 1.1%9.8CVE-2026-41267Flowiseai flowise insecure direct object reference vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…EPSS 0.48%9.8CVE-2026-41268Flowiseai flowise improper input validation vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…EPSS 1.2%9.8CVE-2025-58434Flowise forgot-password endpoint leaks reset token, enabling account takeoverFlowise 3.0.5 and earlier returns a valid password reset tempToken and sensitive account details from the forgot-password endpoint without authentica…EPSS 50%analysed

Source: NIST National Vulnerability Database (record CVE-2024-8181), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.