PT-2026-68776 · Flowise · Flowise

·

CVE-2026-67622

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.5
Description An insecure direct object reference (IDOR) occurs in the OpenAI Assistants integration. This issue allows authenticated attackers to access credentials from other workspaces by providing an arbitrary credential UUID to Assistants endpoints, as the system fails to verify workspace ownership. By exploiting the missing workspace-scoped authorization check in the credential lookup logic, attackers can enumerate assistant metadata across workspaces, retrieve listings for files and vector stores, and upload files into victim workspaces.
Recommendations Update to version 3.1.5 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67622

Affected Products

Flowise