CVE-2024-8181Exploit(flowiseai / flowise)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for flowiseai flowise systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
flowise

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-15: 1Exploit Tool / Code · 2026-04-15: 1Technical Details · 2026-04-15: 104-15
Signal classification1 categories
Exploit
1100.0%
Full discourse1 post
  • NuClide@n15647931
    Exploit

    Flowise < 2.0.5 has a one-character auth bypass (CVE-2024-8181) capitalize /api/ to /API/ and you're in.

    Post summary

    Flowise versions under 2.0.5 contain a one-character authentication bypass (CVE-2024-8181) that can be exploited simply by capitalizing the URL segment /api/ to /API/.

    0000055
    40 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise1.8.2--

Explore more