Skip to content

MCPA-2026-0058

highauth-missingCVSS 7.6

Flowise document store mutation endpoints lack authorization checks (CVE-2026-67621)

Flowise through 3.1.4: the document store upsert and refresh routes are not protected by authorization checks, so workspace members with only view-level permissions can trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows. No fixed release: Flowise announced its sunset; through 3.1.4 (latest) remains affected.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, <= 3.1.4

Identifiers

CVE-2026-67621GHSA-7q53-9j99-gg5cCWE-862

References

Timeline

  • Published: 2026-08-07

← All advisories