Description
Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Tool Access and Execution
Action: Immediate Patch
AI Analysis

Impact

Flowise versions prior to 3.1.4 lack workspace‑level authorization checks on the openai‑realtime endpoints, permitting any authenticated user to supply an unscoped chatflowid and thereby retrieve tool definitions from, and execute tools within, other workspaces. The capability to invoke GET and POST requests exposes sensitive tool outputs and can trigger side‑effects such as external API calls or file operations, compromising both confidentiality and integrity of data stored in those workspaces. The weakness aligns with CWE‑639, an authorization bypass through user‑controlled data.

Affected Systems

The vulnerability affects the FlowiseAI Flowise application in all releases before 3.1.4. All workspaces accessed via openai‑realtime endpoints are potentially vulnerable. Users should verify their deployed Flowise version and apply fixes accordingly.

Risk and Exploitability

With a CVSS score of 7.6, the risk is categorized as High. Exploitation requires only that the attacker be authenticated to the Flowise instance, after which they can construct requests to arbitrary chatflowids. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, though the high severity, lack of restricts, and potential for external side‑effects make it a compelling target for attackers. The known attack vector is over the network using authenticated HTTP or WebSocket connections to the openai‑realtime API.

Generated by OpenCVE AI on September 20, 2026 at 16:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 or later to address all authorization checks on openai‑realtime endpoints.
  • If an immediate upgrade is not possible, enforce strict workspace scoping on chatflowid values at the API gateway or reverse proxy level to prevent cross‑workspace access.
  • Disable or tightly restrict the openai‑realtime endpoints to only trusted, authenticated users that require these capabilities, and monitor usage for tool executions.

Generated by OpenCVE AI on September 20, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.
Title Flowise before 3.1.4 Authorization Bypass via openai-realtime
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-639
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:28:56.360Z

Reserved: 2026-09-15T11:06:02.263Z

Link: CVE-2026-91933

cve-icon Vulnrichment

Updated: 2026-09-17T18:57:11.642Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:44.170

Modified: 2026-09-17T20:18:53.830

Link: CVE-2026-91933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key