Impact
Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that do not verify resource ownership before performing operations. This deficiency allows an attacker with Enterprise access to delete arbitrary workspaces, invite themselves into other organizations, alter cross‑organization roles, and abuse stored SSO secrets; the weakness is classified as CWE‑862.
Affected Systems
The product affected is Flowise by FlowiseAI. All releases before version 3.1.4 are vulnerable. No other product or version details are specified.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. Attackers must first obtain or already possess Enterprise privileges, which limits the attack surface to privileged users or compromised accounts. Since the EPSS score is < 1% and the vulnerability is not in the CISA KEV catalog, the exploitation probability is uncertain but the potential impact across tenants is significant.
OpenCVE Enrichment