Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5x4-4x4f-qgq9

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 7.1

Описание

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.

EPSS

Процентиль: 26%
0.00328
Низкий

7.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.1
nvd
3 дня назад

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.

EPSS

Процентиль: 26%
0.00328
Низкий

7.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-639