Junglewise Threat Intelligence

CVE-2026-100609: Flowise credential lookup authorization bypass

CVE-2026-100609 · Severity: medium · CVSS 6.8 · Published 2026-09-26

Technologies: FlowiseAI Flowise. Vendors: FlowiseAI.

Executive brief

Flowise, an open-source AI workflow platform that manages API credentials for third-party services like OpenAI and ElevenLabs, fails to validate that users can only access credentials within their own workspace. An attacker with any account can submit another user's credential UUID and trick Flowise into decrypting and using that credential to make API calls, potentially gaining unauthorized access to expensive third-party APIs or hijacking AI workflows.

Technical details

The vulnerability is an insecure direct object reference (IDOR) affecting credential lookup across four API endpoints: getAllOpenaiAssistants, uploadFilesToAssistant, deleteAssistant, and getVoices. Each endpoint uses findOneBy({ id: credentialId }) without filtering by workspaceId, allowing any authenticated user to supply a foreign credential UUID and trigger decryption and use of that workspace's API key. The attack requires authentication and knowledge of a valid credential UUID from another workspace; exploitation is verified through error differential analysis showing successful credential use.

Affected products

  • FlowiseAI flowise through 3.1.4
  • FlowiseAI flowise-components through 3.1.4

Timeline

  • 2026-09-26: disclosed

References

Related threats