WebSocket Connection Vulnerability in AppFlowy-Cloud by AppFlowy
CVE-2026-85622

6MEDIUM

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85622?

AppFlowy-Cloud versions up to 0.9.64 contain a serious vulnerability that allows authenticated users to bypass workspace membership checks when establishing WebSocket connections. This flaw enables attackers to send specific sync Manifest messages with victim object identifiers, granting them the ability to access and read confidential document or database states from other workspaces without the knowledge or consent of the workspace members. The issue arises in the establish_ws_connection_v2 handler, leading to unauthorized cross-workspace collaboration and potential data breaches.

Affected Version(s)

AppFlowy-Cloud 0 <= 0.9.64

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.