
Flowise < 2.0.5 has a one-character auth bypass (CVE-2024-8181) capitalize /api/ to /API/ and you're in.
Post summary
Flowise versions under 2.0.5 contain a one-character authentication bypass (CVE-2024-8181) that can be exploited simply by capitalizing the URL segment /api/ to /API/.
