Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.5

CVE-2026-67622: Flowise through 3.1.4: Insecure Access to Other Workspaces

CVE-2026-67622 · published 28 days ago
Summary

An attacker with a Flowise account can access and manipulate files and settings from other workspaces by exploiting a flaw in the integration with OpenAI Assistants. This could lead to unauthorized data access or changes. To protect your workspace, ensure that you only grant access to trusted users and update to the latest version of Flowise as soon as it's available.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
flowiseai flowise <= 3.1.4
Original advisory text
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.
Severity
8.5 High
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 8.5 (NVD)
CVSS 4.0: 7.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published6 Aug 2026
Updated1 Sep 2026
First seen6 Aug 2026
Sources
CVE-2026-67622 · MITRE
Monitor software like this
Free during beta