Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

CVE-2026-100605: Flowise 3.1.4 allows low‑privilege keys to read/delete chats

CVE-2026-100605 · published 14 days ago
Summary

In Flowise versions up to 3.1.4, API keys that are meant to have limited rights can still call the chat message functions and view or erase past conversations. This could let someone see private prompts and model replies or remove important records. Upgrade to the latest Flowise release and review API key permissions, limiting access to only the functions each key truly needs.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
flowiseai flowise <= 3.1.4
Original advisory text
Flowise through 3.1.4 Missing Authorization via Chat Message Routes
Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
7.5 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published26 Sep 2026
Updated9 Oct 2026
First seen26 Sep 2026
Sources
CVE-2026-100605 · MITRE
Track software like this
Free during beta