Executive brief
Flowise, a low-code platform for building conversational AI applications, resolves user accounts based solely on email address across multiple SSO providers without storing provider identity bindings. An attacker can take over any user account by authenticating through a different SSO provider or local password with that user's email address, gaining access to all chatflows, stored credentials, and API keys.
Technical details
The vulnerability exists in SSOBase.verifyAndLogin() which resolves users by email alone (userService.readUserByEmail()) without checking the provider-issued subject identifier (sub) or maintaining (provider, sub) bindings. When a verified email claim arrives from any SSO provider (Google, Auth0, Azure AD, GitHub) or local password, the system grants session access to the matching email account regardless of how it was originally registered. The fix requires storing (provider, sub) bindings and rejecting unrecognized provider-subject pairs rather than auto-merging accounts by email.
Affected products
- FlowiseAI Flowise through 3.1.4
Timeline
- 2026-09-26: disclosed