Executive brief
FlowiseAI is an open-source tool used to build LLM-based applications. A security flaw in the OpenAI Assistants Vector Store component allows any user with basic login access to create, modify, or delete data stores and their associated files. This could lead to the unauthorized exposure of sensitive documents or the disruption of AI-driven business processes.
Technical details
A missing authorization vulnerability (CWE-862/CWE-306) exists in FlowiseAI versions up to 3.1.1. The OpenAI Assistants Vector Store CRUD endpoints, located at `/api/v1/openai-assistants-vector-store`, lack the `checkAnyPermission()` middleware. While these routes require an API key for access, they do not verify the specific permissions or roles of the authenticated user. Consequently, any user with a valid API key can create, update, delete, or upload files to vector stores, potentially leading to data exfiltration or integrity compromise. The issue is addressed in version 3.1.2.
Affected products
- FlowiseAI flowise <= 3.1.1
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory
- 2026-05-14: patched: Fixed in version 3.1.2