Kaitan ID Security[verified]@KaitanSecurityDisclosure
A new high‑severity vulnerability (CVE‑2026‑67622) in Flowise 3.1.4 is disclosed with an insecure direct object reference flaw, but no patch or exploit is yet available.
Upwind Security MDR[verified]@UpwindMDRDisclosure
Flowise OpenAI Assistants up to version 3.1.4 suffer from an IDOR vulnerability that lets authenticated attackers swap credential UUIDs to access other workspaces, enabling enumeration and file uploads, with no fix mentioned yet.
CVE@CVEnewDisclosure
The text announces CVE-2026-67622, describing an insecure direct object reference flaw in Flowise 3.1.4, but provides no PoC, exploit code, active exploitation evidence, or patch information.
ThreatAft@ThreatAftDisclosure
The post announces a high‑severity IDOR vulnerability (CVE‑2026‑67622) in Flowise 3.1.4 that enables cross‑workspace credential theft, notes the lack of an available fix, and urges users to restrict assistant permissions as a temporary mitigation.
Infoflowcloud@infoflowcloudDisclosure
The text discloses CVE-2026-67622, an insecure direct object reference in Flowise 3.1.4's OpenAI Assistants integration that allows authenticated attackers to access restricted data; it provides technical details but no PoC, exploit, patch, or evidence of active exploitation.