logo

Hundreds of LLM Servers Expose Corporate, Health & Other Online Data

ID: 863e1dfe-0eb2-5b09-8519-bf58e3660c87

STIX ID: report--863e1dfe-0eb2-5b09-8519-bf58e3660c87

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-28

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A researcher scanned the web and found hundreds of Flowise LLM builder instances and roughly 30 vector database servers improperly secured; using a known authentication-bypass vulnerability (CVE-2024-31621) the researcher accessed dozens of Flowise servers and discovered exposed GitHub tokens, OpenAI API keys, plaintext passwords, and application data, while open vector DBs contained PII, corporate documents, medical data, and other sensitive content—risks include credential theft, data exfiltration, and poisoning or tampering of AI data stores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.