CVE-2024-8182: high-severity vulnerability in FlowiseAI Flowise
Flowise Denial of Service
Published
26Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 14%
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
FlowiseAI · FlowiseRelated CVEs — FlowiseAI Flowise
In the same product, most dangerous first.
CVE-2025-59528CRITICALFlowise has Remote Code Execution vulnerabilityEPSS 86.2%CVE-2025-58434CRITICALFlowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account TakeoverEPSS 49.9%CVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2025-50538HIGHCVE-2025-50538EPSS 14.0%CVE-2025-61913CRITICALFlowise is vulnerable to arbitrary file read, arbitrary file writeEPSS 13.0%CVE-2025-61687HIGHFlowiseAI/Flosise has File Upload vulnerabilityEPSS 11.1%