MCPA-2026-0058
highauth-missingCVSS 7.6
Flowise document store mutation endpoints lack authorization checks (CVE-2026-67621)
Flowise through 3.1.4: the document store upsert and refresh routes are not protected by authorization checks, so workspace members with only view-level permissions can trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows. No fixed release: Flowise announced its sunset; through 3.1.4 (latest) remains affected.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, <= 3.1.4 |
Identifiers
CVE-2026-67621GHSA-7q53-9j99-gg5cCWE-862
References
- advisory https://github.com/advisories/GHSA-7q53-9j99-gg5c
- web https://nvd.nist.gov/vuln/detail/CVE-2026-67621
- web https://flowiseai.com/sunset
Timeline
- Published: 2026-08-07