Executive brief
Flowise, a platform used to build and manage AI agents visually, contains a security flaw that allows unauthorized individuals to bypass login requirements. An attacker could use this to gain administrative access to the system's API, potentially allowing them to view sensitive data or modify AI workflows. This could lead to a complete takeover of the AI automation environment and disruption of business operations.
Technical details
An authentication bypass vulnerability (CWE-287/CWE-285) exists in Flowise versions prior to 2.0.6. The flaw allows a remote, unauthenticated attacker to bypass security checks and interact with API endpoints as an administrator. By exploiting this, an attacker can access restricted functionality and sensitive data within the Flowise environment. The vulnerability is reachable over the network without user interaction. Users are advised to upgrade to Flowise version 2.0.6 or later to remediate the issue.
Affected products
- FlowiseAI Flowise < 2.0.6
Timeline
- 2024-06-13: other: Tenable first attempted to contact the vendor
- 2024-08-27: disclosed: Initial advisory release
- 2024-08-27: advisory
- 2024-09-04: patched: Solution updated to version 2.0.6