{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aflowiseflowise/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:flowise:flowise:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-100605"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flowise (\u003c= 3.1.4)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","api-security","rbac","authentication-bypass","identity-management","sso","idor","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Flowise"],"content_html":"\u003cp\u003eFlowise versions through 3.1.4 contain a critical authorization vulnerability originating from missing route-level Role-Based Access Control (RBAC) checks on chat message endpoints. This vulnerability allows attackers in possession of low-privileged API keys to bypass intended permission restrictions. By targeting specific GET and DELETE API routes, an unauthorized actor can access chat histories, internal prompts, and model responses, or perform destructive actions by deleting message logs without holding the necessary flow permissions. This defect significantly impacts the confidentiality and integrity of sensitive chat data managed within the Flowise environment. Organizations deploying Flowise should treat this as a high-priority security concern.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows low-privileged users to bypass access control constraints, leading to the unauthorized exfiltration of sensitive AI prompts and customer chat history. Furthermore, the ability to issue DELETE requests to the message endpoints permits attackers to disrupt or purge chat logs, which may impact audit trails and service availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the Flowise API to trusted internal networks while awaiting official patches.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal patterns of GET or DELETE requests to chat message endpoints originating from known low-privileged service accounts or API keys.\u003c/li\u003e\n\u003cli\u003eUpgrade to the latest version of Flowise as soon as a security update is released by the maintainer.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T15:01:41Z","date_published":"2026-09-26T15:00:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-flowise-rbac-vuln/","summary":"Flowise versions up to 3.1.4 are vulnerable to unauthorized access due to missing route-level RBAC checks, allowing low-privileged API keys to read and delete sensitive chat history.","title":"Authorization Bypass in Flowise Chat Message Endpoints","url":"https://feed.craftedsignal.io/briefs/2026-09-flowise-rbac-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:flowise:flowise:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}