Impact
The vulnerability is a missing authorization check in the bulk publish endpoint of AppFlowy-Cloud, allowing any authenticated user to publish content into any workspace’s namespace. Attackers can create published views with attacker‑controlled titles, bodies and metadata, thereby defacing public pages or hosting phishing content on trusted URLs. The impact includes loss of content integrity, potential defacement, and the ability to lure users into phishing attacks.
Affected Systems
AppFlowy-IO’s AppFlowy‑Cloud versions 0.7.2 through 0.9.64 are affected. Users deployed within this version range do not enforce workspace‑level authorization on the bulk publish endpoint and are therefore susceptible to cross‑tenant publishing.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is authenticated API requests to the bulk publish endpoint, and the weakness is identified as CWE‑862: Authorization Control.
OpenCVE Enrichment