Impact
The software version 0.9.64 of AppFlowy-Cloud does not verify that queued collaboration objects belong to the requesting workspace in its authorization checks. This flaw permits an attacker to supply a victim’s object identifier along with an attacker’s own workspace identifier, thereby bypassing collab access controls. Once bypassed, the attacker can read, modify, or delete documents and database rows that belong to other workspaces, compromising confidentiality, integrity, and availability of cross‑workspace data. The weakness is categorized as a missing or inaccurate permission check, CWE-863.
Affected Systems
AppFlowy-IO AppFlowy-Cloud version 0.9.64 is affected. No other versions or vendors are listed in the current advisory.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no public exploitation at the time of this analysis. The likely attack vector is an external network attacker using the exposed HTTP API to supply malicious requests. Because the flaw stems from missing authorization verification, any entity with network access to the API can potentially exploit it, leading to unauthorized data disclosure or modification across workspaces.
OpenCVE Enrichment