Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-100610: Flowise upsert-history can be read or deleted by any user

CVE-2026-100610 · published 14 days ago
Summary

In Flowise versions up to 3.1.4, the web endpoints that show or remove upsert‑history do not verify who is allowed to use them. Because of this, any logged‑in user or holder of a valid API key can view or erase another user’s history data if they know the chatflow identifier or record IDs. To protect your data, limit who can call these endpoints, monitor for unexpected access, and apply a custom fix or wait for an official update that adds proper permission checks.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
flowiseai flowise <= 3.1.4
Original advisory text
Flowise through 3.1.4 Missing Authorization via upsert-history
Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows selected solely by an attacker-supplied chatflowid, and patchDeleteUpsertHistory() deletes rows by an attacker-supplied array of record UUIDs. As a result, any authenticated low-privilege user or valid API key can read or delete document-store upsert history belonging to other users and other workspaces whenever the target chatflowId (which is exposed publicly in /chatbot/<chatflowId> share links) or row ids are known. The retrievable flowData and result fields contain embedding, record-manager and vector-store node configuration, including per-node paramValues. No patched version is available.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
7.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published26 Sep 2026
Updated9 Oct 2026
First seen26 Sep 2026
Sources
CVE-2026-100610 · MITRE
Track software like this
Free during beta