Privilege Escalation Vulnerability in Flowise by FlowiseAI
CVE-2026-30820
8.7HIGH
What is CVE-2026-30820?
Flowise, a drag & drop interface for building custom large language model flows, is susceptible to an authorization bypass vulnerability. Prior to version 3.0.13, Flowise accepts any HTTP client that sets the 'x-request-from: internal' header, enabling a low-privilege tenant to bypass critical authorization checks. This flaw allows unauthorized access to internal administration endpoints, such as API key management, credential stores, and custom function execution, solely with a browser cookie. The issue is addressed in version 3.0.13.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Flowise < 3.0.13
