Description
ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations. | |
| Title | ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via /workflow/search | |
| First Time appeared |
Pandarobot
Pandarobot ruoyi Ai |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:pandarobot:ruoyi_ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pandarobot
Pandarobot ruoyi Ai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T15:04:58.390Z
Reserved: 2026-10-09T13:44:40.884Z
Link: CVE-2026-108111
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization