In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and… (CVE-2026-90534)
Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The selected credential is resolved by raw Credential.id via getCredentialData() and decrypted without verifying Credential.workspaceId against the caller's active or shared workspace, unlike other credential read paths which are workspace-scoped. As a result, an authenticated low-privilege user (or workspace API key) in one workspace can supply a credential ID owned by another workspace and cause Flowise to act as a confused deputy, performing third-party provider calls with the victim workspace's credential and returning provider metadata to the attacker. Statically identified affected load methods include Google Drive listFiles, Google Sheets listSpreadsheets, and AWS DynamoDB KV Storage listTables. The raw credential secret itself is not returned to the attacker. This issue is fixed in version 3.1.4.
AI Analysis
Technical Summary
In Flowise versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is exposed without route-level permission checks. It invokes component loadMethods with attacker-controlled parameters including nodeName, loadMethod, inputs, and credential value. The credential is resolved by raw Credential.id and decrypted without verifying the Credential.workspaceId against the caller's workspace, unlike other credential read paths. Consequently, an authenticated low-privilege user or workspace API key can supply a credential ID from another workspace, causing Flowise to act as a confused deputy by making third-party provider calls using the victim workspace's credentials and returning provider metadata to the attacker. Affected load methods include Google Drive listFiles, Google Sheets listSpreadsheets, and AWS DynamoDB KV Storage listTables. The raw credential secret is not disclosed. The issue is resolved in Flowise version 3.1.4.
Potential Impact
An authenticated low-privilege user or workspace API key can misuse credentials from other workspaces to perform actions on third-party providers as if they were the victim workspace. This can lead to unauthorized third-party provider calls and disclosure of provider metadata. The raw credential secrets themselves are not exposed. This elevates privilege within the application context and can lead to unauthorized access to external services.
Mitigation Recommendations
Upgrade Flowise to version 3.1.4 or later, where this vulnerability is fixed. Until then, restrict access to the affected endpoint to trusted users only. No other official mitigation is documented.
In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and… (CVE-2026-90534)
Description
Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The selected credential is resolved by raw Credential.id via getCredentialData() and decrypted without verifying Credential.workspaceId against the caller's active or shared workspace, unlike other credential read paths which are workspace-scoped. As a result, an authenticated low-privilege user (or workspace API key) in one workspace can supply a credential ID owned by another workspace and cause Flowise to act as a confused deputy, performing third-party provider calls with the victim workspace's credential and returning provider metadata to the attacker. Statically identified affected load methods include Google Drive listFiles, Google Sheets listSpreadsheets, and AWS DynamoDB KV Storage listTables. The raw credential secret itself is not returned to the attacker. This issue is fixed in version 3.1.4.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Flowise versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is exposed without route-level permission checks. It invokes component loadMethods with attacker-controlled parameters including nodeName, loadMethod, inputs, and credential value. The credential is resolved by raw Credential.id and decrypted without verifying the Credential.workspaceId against the caller's workspace, unlike other credential read paths. Consequently, an authenticated low-privilege user or workspace API key can supply a credential ID from another workspace, causing Flowise to act as a confused deputy by making third-party provider calls using the victim workspace's credentials and returning provider metadata to the attacker. Affected load methods include Google Drive listFiles, Google Sheets listSpreadsheets, and AWS DynamoDB KV Storage listTables. The raw credential secret is not disclosed. The issue is resolved in Flowise version 3.1.4.
Potential Impact
An authenticated low-privilege user or workspace API key can misuse credentials from other workspaces to perform actions on third-party providers as if they were the victim workspace. This can lead to unauthorized third-party provider calls and disclosure of provider metadata. The raw credential secrets themselves are not exposed. This elevates privilege within the application context and can lead to unauthorized access to external services.
Mitigation Recommendations
Upgrade Flowise to version 3.1.4 or later, where this vulnerability is fixed. Until then, restrict access to the affected endpoint to trusted users only. No other official mitigation is documented.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wfvf-r9gr-6qfq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90534"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa5f00055bf5e2cf5ef7863
Added to database: 09/13/2026, 00:36:16 UTC
Last enriched: 09/13/2026, 00:38:59 UTC
Last updated: 09/13/2026, 03:01:23 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.