PT-2026-71428 · Flowise · Flowise

·

CVE-2026-73488

·

Published

2026-08-04

·

Updated

2026-08-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.3
Description An insecure direct object reference occurs in the 'GET /api/v1/organization/customer-default-source' endpoint. Authenticated attackers can access payment and profile data of other customers by manipulating the customerId parameter. By enumerating predictable customer IDs, unauthorized users can retrieve sensitive information such as email addresses, account balances, currency types, and billing configurations.
Recommendations Update to version 3.1.3 or later. Avoid using the customerId parameter in the 'GET /api/v1/organization/customer-default-source' endpoint until the update is applied.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73488
GHSA-2364-JH4Q-M9VM

Affected Products

Flowise