Missing Authorization Vulnerability in Flowise by Flowise AI
CVE-2026-71962
Key Information:
Badges
What is CVE-2026-71962?
Flowise versions 2.2.4 through 3.1.4 are vulnerable to a missing authorization issue in the POST /api/v1/openai-assistants-file/download endpoint. This flaw permits unauthenticated attackers to access private files by taking advantage of the endpoint's improper handling of session and API key verification. As the endpoint is included in the global authentication whitelist, attackers can exploit this to retrieve files from any chatflow by supplying valid identifiers like chatflowId, chatId, and fileName, potentially compromising private chatflows across different organizations or workspaces.
Affected Version(s)
Flowise 2.2.4 <= 3.1.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
