WebSocket Connection Vulnerability in AppFlowy-Cloud by AppFlowy
CVE-2026-85622
6MEDIUM
What is CVE-2026-85622?
AppFlowy-Cloud versions up to 0.9.64 contain a serious vulnerability that allows authenticated users to bypass workspace membership checks when establishing WebSocket connections. This flaw enables attackers to send specific sync Manifest messages with victim object identifiers, granting them the ability to access and read confidential document or database states from other workspaces without the knowledge or consent of the workspace members. The issue arises in the establish_ws_connection_v2 handler, leading to unauthorized cross-workspace collaboration and potential data breaches.
Affected Version(s)
AppFlowy-Cloud 0 <= 0.9.64
