Impact
Flowise before version 3.1.4 contains an authentication‑level flaw that allows users to supply arbitrary organization identifiers to its enterprise organization and workspace APIs. The application does not enforce tenant boundaries, so an attacker can add themselves as an owner of any organization, create new workspaces, and thereby gain full administrative control within that organization. The weakness corresponds to CWE‑266, reflecting excessive privileges granted to users.
Affected Systems
The vulnerable software is Flowise from FlowiseAI, any deployment running Flowise version earlier than 3.1.4. All tenants hosted on the same instance are potentially impacted if an authenticated user can target organization and workspace endpoints.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. EPSS data indicates a very low but non‑zero probability of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. Attackers must be authenticated and can inject arbitrary organization IDs into API requests to the organizationuser and workspace endpoints, bypassing tenant isolation and elevating privileges to organization owner status.
OpenCVE Enrichment