Access Control Flaw in Flowise by FlowiseAI
CVE-2026-69252
7.2HIGH
What is CVE-2026-69252?
The Flowise platform exposes a significant access control vulnerability in its API. Prior to version 3.1.3, the /api/v1/files endpoint was inadequately protected, allowing low-privileged authenticated users to execute GET and DELETE requests without proper permission checks. This oversight enabled attackers to list files associated with an organization's storage root and remove files from other workspaces within the same organization using manipulated paths. The issue has been resolved in version 3.1.3, but users of earlier versions should upgrade immediately to secure their systems against unauthorized access.
Affected Version(s)
Flowise < 3.1.3
