Impact
Flowise versions prior to 3.1.4 lack workspace‑level authorization checks on the openai‑realtime endpoints, permitting any authenticated user to supply an unscoped chatflowid and thereby retrieve tool definitions from, and execute tools within, other workspaces. The capability to invoke GET and POST requests exposes sensitive tool outputs and can trigger side‑effects such as external API calls or file operations, compromising both confidentiality and integrity of data stored in those workspaces. The weakness aligns with CWE‑639, an authorization bypass through user‑controlled data.
Affected Systems
The vulnerability affects the FlowiseAI Flowise application in all releases before 3.1.4. All workspaces accessed via openai‑realtime endpoints are potentially vulnerable. Users should verify their deployed Flowise version and apply fixes accordingly.
Risk and Exploitability
With a CVSS score of 7.6, the risk is categorized as High. Exploitation requires only that the attacker be authenticated to the Flowise instance, after which they can construct requests to arbitrary chatflowids. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, though the high severity, lack of restricts, and potential for external side‑effects make it a compelling target for attackers. The known attack vector is over the network using authenticated HTTP or WebSocket connections to the openai‑realtime API.
OpenCVE Enrichment