<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Flowise Enterprise (&lt; 3.1.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/flowise-enterprise--3.1.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 17:42:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/flowise-enterprise--3.1.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Flowise Cross-Tenant Authorization Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-flowise-auth-gap/</link><pubDate>Tue, 15 Sep 2026 17:42:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-flowise-auth-gap/</guid><description>Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.</description><content:encoded><![CDATA[<p>Flowise versions prior to 3.1.4 are affected by critical cross-tenant authorization flaws within their Enterprise endpoint implementations. The vulnerability arises from a failure to validate resource ownership during API operations. An attacker who has legitimate access to an Enterprise instance can exploit these endpoints to interact with resources belonging to other tenants within the same installation.</p>
<p>Successful exploitation allows for a range of unauthorized activities, including the deletion of arbitrary workspaces, unauthorized self-invitation into external organizations, modification of cross-organization roles, and the retrieval of stored Single Sign-On (SSO) secrets. Given the potential for complete control over tenant configuration and the exposure of sensitive authentication material, this vulnerability poses a high risk to organizations utilizing Flowise Enterprise.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows authenticated attackers to compromise the confidentiality, integrity, and availability of multi-tenant Flowise environments. Impact includes the destruction of victim workspace data, potential account takeovers via cross-org role escalation, and the compromise of sensitive SSO configuration secrets, which could lead to further downstream attacks against integrated corporate identity providers.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update all Flowise Enterprise instances to version 3.1.4 or later immediately.</li>
<li>Review audit logs for anomalous API requests targeting organization management endpoints or role modifications that appear outside of authorized administrative workflows.</li>
<li>Monitor for unauthorized workspace deletions or suspicious additions of new users to high-privilege organization roles.</li>
<li>Rotate all SSO secrets and configuration keys stored within Flowise Enterprise if there is suspicion that an unauthenticated or unauthorized actor accessed the system prior to patching.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>xss</category><category>vulnerability</category><category>nosql-injection</category><category>web-application</category><category>ssrf</category><category>privilege-escalation</category><category>tenant-isolation</category><category>api-vulnerability</category></item></channel></rss>