Junglewise Threat Intelligence

FlowiseAI missing authorization in OpenAI Assistants Vector Store

Severity: high · CVSS 8.7 · Published 2026-05-14

Technologies: flowise (npm). Vendors: npm.

Executive brief

FlowiseAI is an open-source tool used to build customized LLM orchestration flows. A security flaw in the OpenAI Assistants Vector Store component allows any user with basic login access to create, modify, or delete data stores and files. This could lead to unauthorized data access, the deletion of critical information, or the injection of malicious documents into the AI's knowledge base.

Affected products

  • npm flowise

Related threats