Insecure Direct Object Reference in Flowise from FlowiseAI
CVE-2026-100609
7.6HIGH
What is CVE-2026-100609?
Flowise versions up to 3.1.4 exhibit an Insecure Direct Object Reference vulnerability, allowing authenticated users to access credentials across different workspaces without proper authorization checks. The issue arises when users can manipulate API calls, such as fetching or deleting OpenAI assistants and uploading files, using credential IDs linked to other workspaces. This flaw can lead to unauthorized access to sensitive API keys, compromising the security of affected users and their workspaces. As of the time of this notification, no patched version is available, making it essential for users to implement immediate protective measures.
Affected Version(s)
Flowise 0 <= 3.1.4
Flowise 0 <= 3.1.4
