Impact
Flowise versions prior to 3.1.3 contain an insecure direct object reference in the GET /api/v1/organization/customer-default-source endpoint. The flaw permits authenticated users to modify the customerId parameter and obtain confidential information belonging to other customers, such as email addresses, account balances, currency types, and billing configurations. This vulnerability leads to unauthorized disclosure of sensitive data and potentially exposes financial and personal information without proper authorization checks.
Affected Systems
The affected product is Flowise AI – Flowise. All releases before version 3.1.3 are vulnerable. Users running the affected application should verify their installed version and, if it falls below 3.1.3, consider upgrading. The CPE identifier for the product is cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*, indicating the vulnerability affects the Flowise standalone application.
Risk and Exploitability
The vulnerability has a CVSS score of 6, reflecting moderate severity. The EPSS score is not available, so the exploitation probability cannot be precisely quantified. It is not listed in CISA’s KEV catalog, suggesting no actively known exploits at this time. Attackers must be authenticated and can exploit the vulnerability by sending crafted requests to the customer-default-source endpoint, manipulating the customerId parameter to enumerate predictable identifiers. The primary attack vector is HTTP GET, and the required conditions include valid user credentials and network access to the API.
OpenCVE Enrichment