Missing Authorization in Flowise - CVE-2026-70473
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in GET /api/v1/upsert-history when handling requests for upsert history data. A remote user can send a request to the endpoint to disclose sensitive information.
The response may include server-wide upsert history and sensitive configuration details such as vector store endpoint URLs, collection names, and schema-related parameters.