VDB
KO
HIGH 7.3

GHSA-2q4w-x8h2-2fvh

Flowise Authentication Bypass vulnerability

Details

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / flowise
Introduced in: 0

No fixed version published yet for flowise (npm). Pin to a known-safe version or switch to an alternative.

References