Authorization bypass through user-controlled key in Flowise - #VU146549

 

Authorization bypass through user-controlled key in Flowise - #VU146549

Published: September 1, 2026


Vulnerability identifier: #VU146549
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose tool definitions, execute tools, and obtain tool outputs across workspace boundaries.

The vulnerability exists due to authorization bypass through a user-controlled key in the openai-realtime GET and POST endpoints when handling a supplied chatflow ID without verifying workspace ownership. A remote user can supply a victim chatflow ID to access another workspace\'s ChatFlow runtime objects and invoke associated tools to disclose tool definitions, execute tools, and obtain tool outputs across workspace boundaries.

Exploitation is limited to users or API keys within the same Flowise organization, and tool execution can trigger external side effects depending on the victim workspace configuration.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins