Junglewise Threat Intelligence

CVE-2026-56268: Flowise cross-workspace information disclosure in chatflows API

CVE-2026-56268 · Severity: high · CVSS 7.7 · Published 2026-06-22

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a security flaw that allows users in one workspace to view sensitive data from other workspaces. By using a valid API key, an attacker can access the full configuration of any chatbot that does not have its own specific API key assigned. This could lead to the exposure of proprietary system prompts, internal workflow logic, and configuration details belonging to other teams or organizations using the same installation.

Technical details

An information disclosure vulnerability exists in Flowise versions prior to 3.1.2 due to incorrect authorization logic in the `/api/v1/chatflows/apikey/:apikey` endpoint. When the `keyonly` query parameter is omitted, the backend service executes a database query that retrieves chatflows associated with the provided API key as well as all chatflows where the API key ID is NULL or empty. Because the query lacks a workspace-level filter, it returns unprotected chatflows from every workspace in the system. An authenticated attacker with a valid API key for any workspace can exploit this to retrieve full ChatFlow configurations, including `flowData` (system prompts, node configurations), `chatbotConfig`, and credential IDs. The issue is fixed in version 3.1.2 by adding workspace scoping to the database query.

Affected products

  • FlowiseAI Flowise < 3.1.2

Timeline

  • 2026-05-14: advisory: GitHub Security Advisory published
  • 2026-06-22: disclosed: NVD publication date

References

Related threats