Junglewise Threat Intelligence

CVE-2024-8182: Flowise unauthenticated denial of service in file upload endpoint

CVE-2024-8182 · Severity: low · CVSS 3.1 · Published 2024-08-27

Technologies: flowise (npm). Vendors: npm, Flowise.

Executive brief

Flowise is a visual AI agent builder used to create and deploy intelligent automation workflows. An unauthenticated attacker can crash the entire Flowise instance by sending a specially crafted request to the file upload API endpoint, rendering the service unavailable to all users and disrupting business operations that depend on the platform.

Technical details

An unauthenticated denial of service vulnerability exists in Flowise version 1.8.2 in the /api/v1/get-upload-file endpoint due to improper handling of user-supplied input. The vulnerability is classified as CWE-400 (uncontrolled resource consumption). An attacker can send a crafted request to this endpoint without authentication to trigger a complete crash of the Flowise instance. The attack vector is network-based with no authentication required and no user interaction needed. As of the disclosure date (August 27, 2024), Flowise maintainers had not provided a patch or mitigation strategy despite multiple contact attempts from Tenable beginning in June 2024. The repository has since been archived.

Affected products

  • Flowise Flowise 1.8.2 and all previous versions

Timeline

  • 2024-08-27: disclosed: Vulnerability published by Tenable; CVE-2024-8182 assigned
  • 2024-06-13: other: Tenable first contacted vendor for security contact
  • 2024-08-14: other: Tenable third contact attempt with vendor

References

Related threats