PT-2026-99277 · Flowise · Flowise
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.5
Description
An authentication bypass exists in the SSO login path when Enterprise/platform mode with SSO is enabled. The issue occurs when an SSO callback is received with an email matching a user with an INVITED status. The
verifyAndLogin() function in SSOBase.ts copies the user record, including the server-stored single-use tempToken, into the data sent to AccountService.register(). This causes the token lookup, email match, and expiry checks to pass using the server's own token rather than a token provided by the caller, resulting in the account and organization membership being set to ACTIVE. Consequently, an attacker who can authenticate via a configured SSO provider using a pending invitee's email address can take over the invitation and gain access to the organization without the invitation token, provided the invitation is still valid.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise