Cross-Site Credential Exposure in Flowise by FlowiseAI
CVE-2026-90534

6.1MEDIUM

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90534?

Flowise is a low-code platform that allows users to build LLM applications. A security weakness exists in versions prior to 3.1.4, specifically in the POST /api/v1/node-load-method/:name endpoint, which lacks proper route-level permission checks. This oversight enables an authenticated low-privilege user to exploit the system by using an attacker-controlled nodeName, loadMethod, inputs, and credential values. The vulnerability allows the attacker to access the credentials belonging to another workspace without verifying the ownership. This results in unauthorized third-party provider calls using the victim's credentials, exposing sensitive provider metadata to the attacker. Notably, affected methods include interactions with Google Drive and AWS DynamoDB. The issue has been addressed in version 3.1.4.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

c4tzzz
.