Impact
Flowise up to version 3.1.4 contains an insecure direct object reference flaw in the OpenAI Assistants integration. The flaw allows an authenticated user to supply any credential UUID to Assistants endpoints, bypassing workspace ownership checks. As a result, the attacker can read credential data that belongs to other workspaces, enumerate assistant metadata, retrieve file and vector store listings, and even upload files into victim workspaces through the credential lookup logic.
Affected Systems
The vulnerability is present in Flowise AI's Flowise product, affecting all releases up to and including version 3.1.4. No other versions are known to be impacted based on the current data.
Risk and Exploitability
The CVSS score for this flaw is 8.5, reflecting a high severity due to the broad impact on confidentiality and integrity. EPSS data is not available, so the exact exploitation probability cannot be quantified. The flaw is not listed in the CISA KEV catalog at this time. Attackers must be authenticated against Flowise to exploit the vulnerability, but the missing workspace‑scoped authorization check means a user can target any workspace for which they have access credentials.
OpenCVE Enrichment