Cross-Site Credential Exposure in Flowise by FlowiseAI
CVE-2026-90534
What is CVE-2026-90534?
Flowise is a low-code platform that allows users to build LLM applications. A security weakness exists in versions prior to 3.1.4, specifically in the POST /api/v1/node-load-method/:name endpoint, which lacks proper route-level permission checks. This oversight enables an authenticated low-privilege user to exploit the system by using an attacker-controlled nodeName, loadMethod, inputs, and credential values. The vulnerability allows the attacker to access the credentials belonging to another workspace without verifying the ownership. This results in unauthorized third-party provider calls using the victim's credentials, exposing sensitive provider metadata to the attacker. Notably, affected methods include interactions with Google Drive and AWS DynamoDB. The issue has been addressed in version 3.1.4.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 3.1.4
