Skip to content

MCPA-2026-0057

highauth-missingCVSS 9.9

Flowise OpenAI Assistants IDOR exposes cross-workspace credentials and files (CVE-2026-67622)

Flowise through 3.1.4: the OpenAI Assistants integration looks up credentials by UUID without verifying workspace ownership, so any authenticated user can enumerate cross-workspace assistant metadata, list files and vector stores, and upload files into victim workspaces by supplying arbitrary credential UUIDs. No fixed release: Flowise announced its sunset; through 3.1.4 (latest) remains affected.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, <= 3.1.4

Identifiers

CVE-2026-67622GHSA-qvmw-v4w9-7c4jCWE-639

References

Timeline

  • Published: 2026-08-07

← All advisories