Junglewise Threat Intelligence

CVE-2026-30820: Flowise authorization bypass via spoofed x-request-from header

CVE-2026-30820 · Severity: medium · CVSS 4 · Published 2026-03-06

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise is an open-source workflow automation platform that manages API keys, credentials, and custom functions. An authenticated user can spoof an HTTP header to bypass authorization checks and gain access to privileged administration endpoints, allowing them to create API keys, steal stored secrets, and potentially execute arbitrary code—effectively escalating from a regular user to an administrator.

Technical details

The vulnerability is a missing authorization check (CWE-863) in the global API middleware at index.ts:214. When a request includes the header x-request-from: internal, the middleware trusts it as an internal call and only verifies the session token, without performing any downstream permission checks. An attacker with a valid session cookie can add this spoofable header to reach any /api/v1/** endpoint (API key management, credential stores, custom function execution) that is ordinarily restricted to internal callers. The attack requires only an authenticated tenant session and network access to the Flowise API; no additional privileges or user interaction are needed. Patch available in version 3.0.13.

Affected products

  • FlowiseAI Flowise <= 3.0.12

Timeline

  • 2026-03-06: disclosed
  • 2026-03-13: patched: Fixed in version 3.0.13

References

Related threats