Insecure Direct Object Reference in Flowise from FlowiseAI
CVE-2026-100609

7.6HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100609?

Flowise versions up to 3.1.4 exhibit an Insecure Direct Object Reference vulnerability, allowing authenticated users to access credentials across different workspaces without proper authorization checks. The issue arises when users can manipulate API calls, such as fetching or deleting OpenAI assistants and uploading files, using credential IDs linked to other workspaces. This flaw can lead to unauthorized access to sensitive API keys, compromising the security of affected users and their workspaces. As of the time of this notification, no patched version is available, making it essential for users to implement immediate protective measures.

Affected Version(s)

Flowise 0 <= 3.1.4

Flowise 0 <= 3.1.4

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

akshatgit
.