CPE
Flowise versions up to 3.1.4 are vulnerable to unauthorized access due to missing route-level RBAC checks, allowing low-privileged API keys to read and delete sensitive chat history.