CVE-2026-30824Disclosure(flowiseai / flowise)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch flowiseai flowise systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. This issue has been patched in version 3.0.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-12: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-12: 103-0703-1204-15
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure1Patch1
2026-03-121
Disclosure1
2026-04-151
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-30824 - high 🚨 Flowise - NVIDIA NIM Endpoints Missing Authentication > Flowise is a drag & drop user interface to build a customized large language model fl... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-30824 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-30824 affecting Flowise NVIDIA NIM Endpoints with missing authentication, but provides no proof-of-concept, exploit code, or patch information.

    00001188
    930 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30824 (CVSS:7.7, CRITICAL) is Analyzed. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NV..https://nvd.nist.gov/vuln/detail/CVE-2026-30824 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post summarizes CVE-2026-30824, noting its CVSS 7.7 critical score, indicates Flowise versions before 3.0.13 are vulnerable, and directs readers to the NVD entry for details.

    0000015
    172 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-30824 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whit… https://www.cve.org/CVERecord?id=CVE-2026-30824

    Post summary

    This entry notes a CVE affecting Flowise prior to version 3.0.13, indicating that upgrading to that version resolves the issue. No PoC, exploit code, or active exploitation details are offered.

    00000163
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30824 Unauthenticated Access to Privileged Endpoints in Flowise Before 3.0.13 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30824

    Post summary

    The text announces a CVE against Flowise versions before 3.0.13 that allows unauthenticated access to privileged endpoints; it contains only a brief description without any PoC, exploit code, patch, or active exploitation evidence.

    0000057
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more