CVE-2026-67622Disclosure(flowiseai / flowise)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch flowiseai flowise systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-08-06: 1Mentions · 2026-08-07: 3Mentions · 2026-08-08: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 3Technical Details · 2026-08-08: 108-0608-0708-08
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-061
Disclosure1
2026-08-073
Disclosure3
2026-08-081
Disclosure1
Full discourse5 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration t… CVSS 9.9 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-67622 #OpenAI #CyberSecurity #InfoSec

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑67622) in Flowise 3.1.4 is disclosed with an insecure direct object reference flaw, but no patch or exploit is yet available.

    0101058
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access cr… https://www.cve.org/CVERecord?id=CVE-2026-67622

    Post summary

    The text announces CVE-2026-67622, describing an insecure direct object reference flaw in Flowise 3.1.4, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00001787
    57.9K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 🚨 Flowise IDOR — CVSS 9.9 CVE-2026-67622: Cross-workspace credential theft in OpenAI Assistants integration. Affected ≤ 3.1.4. No fix yet. Restrict assistants permissions NOW. → http://threataft.com/articles/flowise-cve-2026-67622-idor #cybersecurity #infosec #AIsecurity #Flowise #OpenAI #ThreatIntel

    Post summary

    The post announces a high‑severity IDOR vulnerability (CVE‑2026‑67622) in Flowise 3.1.4 that enables cross‑workspace credential theft, notes the lack of an available fix, and urges users to restrict assistant permissions as a temporary mitigation.

    0000067
    36 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Flowise OpenAI Assistants IDOR Credential UUID Swap (CVE-2026-67622) Flowise OpenAI Assistants integration lacks workspace ownership checks on Assistants endpoints, allowing authenticated attackers to pass arbitrary credential UUIDs and access other workspaces’ OpenAI credentials. This enables cross-workspace enumeration of assistant metadata, listing files/vector stores, and uploading files into victim workspaces. 👉Affected: Flowise <= 3.1.4

    Post summary

    Flowise OpenAI Assistants up to version 3.1.4 suffer from an IDOR vulnerability that lets authenticated attackers swap credential UUIDs to access other workspaces, enabling enumeration and file uploads, with no fix mentioned yet.

    0000090
    282 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access cr… https://www.cve.org/CVERecord?id=CVE-2026-67622 ----- Traducción: CVE-2026-67622 Flo… http://infoflow.cloud`

    Post summary

    The text discloses CVE-2026-67622, an insecure direct object reference in Flowise 3.1.4's OpenAI Assistants integration that allows authenticated attackers to access restricted data; it provides technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000062
    98 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more