Executive brief
Flowise, a platform for building and managing conversational workflows, contains an authorization flaw in its SSO (single sign-on) configuration API. Any user with a free account can modify another organization's login settings by simply knowing the target organization ID, allowing attackers to hijack employee logins or unlock premium features without payment.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) combined with missing authorization checks in the PUT /api/v1/loginmethod endpoint. While the endpoint requires authentication (low-privileged JWT token), it accepts an organizationId parameter in the request body and directly updates the database without verifying that the authenticated user belongs to or has administrative rights over that organization. An attacker with any valid account (including free tier) can supply a different organizationId and modify OAuth provider credentials (Google, Azure, Okta) for victim organizations, enabling account takeover by redirecting authentication to attacker-controlled applications or enabling restricted enterprise features. The fix is available in version 3.0.13.
Affected products
- FlowiseAI Flowise <=3.0.12
Timeline
- 2026-03-06: disclosed
- 2026-03-06: patched: Fix released in version 3.0.13