PT-2026-67928 · Npm · Flowise

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

summary:

In Flowise, DELETE /api/v1/chatflows/:id authorizes requests with checkAnyPermission('chatflows:delete,agentflows:delete'). Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW, and a caller with only chatflows:delete to delete an AGENTFLOW.

details:

The delete route accepts either chatflows:delete or agentflows:delete. The subsequent logic only resolves the target record by id and workspaceId, then deletes by id without checking whether the target resource type matches the granted permission domain.
As a result, there is no binding between permission scope and flow type:
  • agentflows:delete can be used to delete CHATFLOW
  • chatflows:delete can be used to delete AGENTFLOW
This breaks the intended RBAC separation between Chatflows and Agentflows.

impact:

Users authorized to manage only one flow type can delete the other flow type within the same workspace, resulting in unauthorized deletion and configuration loss.

reproduction steps:

  1. Log in as a user who can create API keys.
  2. Create a normal CHATFLOW and record its id.
  3. Create an API key with only agentflows:delete.
  4. Use that API key to send:
bash
curl -i -X DELETE 
 -H 'Authorization: Bearer <agentflows delete only key>' 
 http://localhost:8080/api/v1/chatflows/<chatflow id>
  1. Observe a 200 OK response, for example:
json
{"raw":[],"affected":1}
  1. Read the same id again and observe 404 Not Found.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-P5W8-M249-4R4V

Affected Products

Flowise