Vulnerability record · CVE-2024-8181 · published 27 August 2024
CVE-2024-8181: Flowise authentication bypass allows admin API access
Flowiseai · Flowise
Flowise version 1.8.2 contains an improper authentication flaw (CWE-287) that lets a remote, unauthenticated attacker reach API endpoints with administrator privileges. Because the affected endpoints expose restricted functionality, the flaw undermines the product's access control boundary and matters to any deployment reachable from an untrusted network.
Description
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Automated analysis
high priorityCVSS 8.1 with no authentication required and a very high EPSS percentile, though the need for user interaction and absence of confirmed exploitation keep it below critical.
What it is
Flowise version 1.8.2 contains an improper authentication flaw (CWE-287) that lets a remote, unauthenticated attacker reach API endpoints with administrator privileges. Because the affected endpoints expose restricted functionality, the flaw undermines the product's access control boundary and matters to any deployment reachable from an untrusted network.
Impact
An attacker gains administrator-level access to restricted API functionality without valid credentials. That access can be used to read or modify data and configuration exposed through those endpoints.
Attack surface
Reached over the network via the Flowise API (CVSS vector AV:N/AC:L/PR:N/UI:R). No authentication is required, but the vector indicates user interaction is needed, so exploitation likely depends on a victim triggering or visiting something.
Exploitation
No CISA KEV listing and no ransomware associations are recorded. EPSS is high at 0.4505 (98.7th percentile), indicating elevated predicted exploitation activity, but the record contains no public exploit or in-the-wild confirmation.
What to do
- Upgrade Flowise from version 1.8.2 to a fixed release as soon as the vendor provides one; verify the fix against the vendor advisory.
- Restrict network access to Flowise API endpoints to trusted networks or authenticated reverse proxies until patching is complete.
- Enforce authentication and authorization at a fronting proxy or gateway so unauthenticated requests cannot reach the Flowise API directly.
- Audit Flowise administrator accounts and API tokens for unauthorized changes or additions.
- Monitor vendor and Tenable advisories for updated affected-version and patch information.
Detection
- Review Flowise API access logs for requests to administrative endpoints from unauthenticated or unexpected source IPs.
- Alert on successful admin-level API calls that lack a corresponding authenticated session or valid token.
- Baseline normal Flowise API traffic and flag new or anomalous endpoint access patterns.
- Correlate Flowise logs with proxy logs to identify requests that bypassed expected authentication controls.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-8181 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8181), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.