MCPA-2026-0057
highauth-missingCVSS 9.9
Flowise OpenAI Assistants IDOR exposes cross-workspace credentials and files (CVE-2026-67622)
Flowise through 3.1.4: the OpenAI Assistants integration looks up credentials by UUID without verifying workspace ownership, so any authenticated user can enumerate cross-workspace assistant metadata, list files and vector stores, and upload files into victim workspaces by supplying arbitrary credential UUIDs. No fixed release: Flowise announced its sunset; through 3.1.4 (latest) remains affected.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, <= 3.1.4 |
Identifiers
CVE-2026-67622GHSA-qvmw-v4w9-7c4jCWE-639
References
- advisory https://github.com/advisories/GHSA-qvmw-v4w9-7c4j
- web https://nvd.nist.gov/vuln/detail/CVE-2026-67622
- web https://flowiseai.com/sunset
Timeline
- Published: 2026-08-07