Executive brief
Flowise is an enterprise AI workflow automation platform that uses single sign-on (SSO) for user authentication in platform mode. An attacker who can authenticate at any configured SSO provider using a pending invitee's email address can take over an open invitation and gain full access to the invited user's account and organization membership, without needing the invitation token that was emailed to the victim. This makes every pending invitation a potential foothold into enterprise deployments.
Technical details
The vulnerability exists in the SSO verifyAndLogin function (SSOBase.ts:80-94) which passes the server-stored invitation tempToken to the register handler instead of requiring a caller-supplied token. The register validation chain then validates against the database-stored token that was just copied from the user record, rather than an external proof of email ownership, allowing trivial bypass. An attacker needs only an email match at any configured SSO provider; the attack succeeds during the 24-hour invitation window and requires no user interaction beyond SSO authentication.
Affected products
- FlowiseAI Flowise through 3.1.4
Timeline
- 2026-09-26: disclosed
- 2026-09-10: advisory: GitHub Security Advisory GHSA-vf3j-89vf-r697 published