CVE-2026-100610: Authorization Bypass Through User-Controlled Key in FlowiseAI Flowise
Flowise versions up to 3.1.4 have an authorization bypass vulnerability in the /api/v1/upsert-history endpoints. These endpoints lack route-level permission checks and do not validate workspace or ownership, allowing authenticated low-privilege users or valid API keys to read or delete upsert history data belonging to other users or workspaces if they know the chatflowId or record UUIDs. The exposed data includes sensitive configuration details such as embedding and vector-store node parameters. No patch is currently available for this vulnerability.
AI Analysis
Technical Summary
Flowise through version 3.1.4 exposes GET and PATCH endpoints for upsert history without proper authorization controls. The service does not validate workspace or ownership, enabling any authenticated user or API key with knowledge of a chatflowId or record UUIDs to access or delete upsert history records belonging to other users or workspaces. The data exposed includes flowData and result fields containing embedding, record-manager, and vector-store node configurations, including per-node parameter values. This constitutes an authorization bypass vulnerability allowing unauthorized read and delete operations on sensitive data.
Potential Impact
An attacker with low privileges or a valid API key can access and delete upsert history data from other users and workspaces. This unauthorized access exposes sensitive configuration information related to embeddings and vector-store nodes, potentially leading to information disclosure and disruption of data integrity. The vulnerability affects confidentiality and availability of the affected data.
Mitigation Recommendations
No patched version is currently available. Users should restrict access to authenticated users and API keys carefully and monitor usage to detect potential abuse. Follow vendor advisories for updates and apply patches once they are released.
CVE-2026-100610: Authorization Bypass Through User-Controlled Key in FlowiseAI Flowise
Description
Flowise versions up to 3.1.4 have an authorization bypass vulnerability in the /api/v1/upsert-history endpoints. These endpoints lack route-level permission checks and do not validate workspace or ownership, allowing authenticated low-privilege users or valid API keys to read or delete upsert history data belonging to other users or workspaces if they know the chatflowId or record UUIDs. The exposed data includes sensitive configuration details such as embedding and vector-store node parameters. No patch is currently available for this vulnerability.
CVSS v4.0
Score 7.7high
Affected software
FlowiseAI
Flowise
pkg:github/flowiseai/FlowiseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Flowise through version 3.1.4 exposes GET and PATCH endpoints for upsert history without proper authorization controls. The service does not validate workspace or ownership, enabling any authenticated user or API key with knowledge of a chatflowId or record UUIDs to access or delete upsert history records belonging to other users or workspaces. The data exposed includes flowData and result fields containing embedding, record-manager, and vector-store node configurations, including per-node parameter values. This constitutes an authorization bypass vulnerability allowing unauthorized read and delete operations on sensitive data.
Potential Impact
An attacker with low privileges or a valid API key can access and delete upsert history data from other users and workspaces. This unauthorized access exposes sensitive configuration information related to embeddings and vector-store nodes, potentially leading to information disclosure and disruption of data integrity. The vulnerability affects confidentiality and availability of the affected data.
Mitigation Recommendations
No patched version is currently available. Users should restrict access to authenticated users and API keys carefully and monitor usage to detect potential abuse. Follow vendor advisories for updates and apply patches once they are released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:30:34.352Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a1f7a7c5410652fcfb
Added to database: 09/26/2026, 13:33:21 UTC
Last enriched: 09/26/2026, 14:19:10 UTC
Last updated: 09/26/2026, 15:27:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.