Impact
The vulnerability is a missing authorization check on the execution update endpoint, allowing any authenticated user to change the state, data, and metadata of any execution in their workspace. This exposes the system to privilege escalation and the ability to corrupt or manipulate workflow execution results.
Affected Systems
Flowise AI’s Flowise product, versions prior to 3.1.3 are affected; starting with 3.1.3 the issue is fixed.
Risk and Exploitability
The CVSS score is 7.1, indicating a high likelihood of severe impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is authenticated; an attacker only needs valid user credentials within a workspace to exploit the flaw, making the risk high for any organization relying on Flowise for workflow management.
OpenCVE Enrichment
Github GHSA