CVE-2026-69262: CWE-863: Incorrect Authorization in FlowiseAI Flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
FlowiseAI Flowise before version 3.1.3 contains an incorrect authorization vulnerability (CWE-863) in the DELETE /api/v1/chatflows/:id endpoint. The authorization logic uses checkAnyPermission('chatflows:delete,agentflows:delete'), allowing access if the caller has either permission. However, the deletion logic only verifies the target record by id and workspaceId without validating the resource type, enabling a caller with 'agentflows:delete' permission to delete CHATFLOW resources and a caller with 'chatflows:delete' permission to delete AGENTFLOW resources within the same workspace. This improper authorization can lead to unauthorized deletion of resources. The issue is resolved in version 3.1.3.
Potential Impact
An attacker or user with limited delete permissions can delete resources they should not have access to, potentially disrupting workflows or causing data loss within the affected workspace. The vulnerability allows privilege escalation within the scope of delete permissions by bypassing resource type checks.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this authorization flaw is fixed. No other mitigation is indicated by the vendor advisory. Patch status is confirmed fixed in 3.1.3.
CVE-2026-69262: CWE-863: Incorrect Authorization in FlowiseAI Flowise
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.
CVSS v4.0
Score 7.1high
Affected software
FlowiseAI
Flowise
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FlowiseAI Flowise before version 3.1.3 contains an incorrect authorization vulnerability (CWE-863) in the DELETE /api/v1/chatflows/:id endpoint. The authorization logic uses checkAnyPermission('chatflows:delete,agentflows:delete'), allowing access if the caller has either permission. However, the deletion logic only verifies the target record by id and workspaceId without validating the resource type, enabling a caller with 'agentflows:delete' permission to delete CHATFLOW resources and a caller with 'chatflows:delete' permission to delete AGENTFLOW resources within the same workspace. This improper authorization can lead to unauthorized deletion of resources. The issue is resolved in version 3.1.3.
Potential Impact
An attacker or user with limited delete permissions can delete resources they should not have access to, potentially disrupting workflows or causing data loss within the affected workspace. The vulnerability allows privilege escalation within the scope of delete permissions by bypassing resource type checks.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this authorization flaw is fixed. No other mitigation is indicated by the vendor advisory. Patch status is confirmed fixed in 3.1.3.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.853Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a721d52bf8831d53928c5fc
Added to database: 08/04/2026, 17:11:46 UTC
Last enriched: 08/11/2026, 17:58:33 UTC
Last updated: 09/18/2026, 02:30:22 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.