Improper access control in Flowise - #VU140053

 

Improper access control in Flowise - #VU140053

Published: July 30, 2026


Vulnerability identifier: #VU140053
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the NodeVM sandbox allowlist and /api/v1/node-custom-function endpoint when processing authenticated user-supplied JavaScript that loads puppeteer. A remote user can submit crafted JavaScript that uses Chromium file:// navigation through puppeteer to disclose sensitive information.

The issue allows reading files accessible to the Flowise process user and returning their contents in the API response.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins