PT-2026-69899 · Flowiseai+1 · Flowise
CVE-2026-71962
·
Published
2026-08-10
·
Updated
2026-08-10
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions 2.2.4 through 3.1.4
Description
An authorization flaw exists in the 'POST /api/v1/openai-assistants-file/download' endpoint. Because this endpoint is included in the global authentication whitelist, it bypasses session and API key verification, allowing unauthenticated access. An attacker can retrieve private files from any chatflow on the instance, including those from other workspaces or organizations, by providing valid
chatflowId, chatId, and fileName identifiers.Recommendations
Update Flowise to a version later than 3.1.4.
As a temporary mitigation, restrict access to the 'POST /api/v1/openai-assistants-file/download' endpoint.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise