/Vulnerability Library

Flowise - NVIDIA NIM Endpoints Missing Authentication

CVE-2026-30824
Verified

Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints.

Severity

High

CVSS Score

8.6

Exploit Probability

3%

Affected Product

flowise

Published Date

April 15, 2026

Template Author

dhiyaneshdk

CVE-2026-30824.yaml
8.6Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE ID:
cve-2026-30824
CWE ID:
cwe-306

References

https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5f53-522j-j454https://nvd.nist.gov/vuln/detail/CVE-2026-30824https://github.com/FlowiseAI/Flowise

Remediation Steps

This issue has been patched in version 3.0.13