Junglewise Threat Intelligence

CVE-2024-8181: FlowiseAI Flowise authentication bypass in API endpoints

CVE-2024-8181 · Severity: low · CVSS 3.1 · Published 2024-08-27

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise, a platform used to build and manage AI agents visually, contains a security flaw that allows unauthorized individuals to bypass login requirements. An attacker could use this to gain administrative access to the system's API, potentially allowing them to view sensitive data or modify AI workflows. This could lead to a complete takeover of the AI automation environment and disruption of business operations.

Technical details

An authentication bypass vulnerability (CWE-287/CWE-285) exists in Flowise versions prior to 2.0.6. The flaw allows a remote, unauthenticated attacker to bypass security checks and interact with API endpoints as an administrator. By exploiting this, an attacker can access restricted functionality and sensitive data within the Flowise environment. The vulnerability is reachable over the network without user interaction. Users are advised to upgrade to Flowise version 2.0.6 or later to remediate the issue.

Affected products

  • FlowiseAI Flowise < 2.0.6

Timeline

  • 2024-06-13: other: Tenable first attempted to contact the vendor
  • 2024-08-27: disclosed: Initial advisory release
  • 2024-08-27: advisory
  • 2024-09-04: patched: Solution updated to version 2.0.6

References

Related threats