Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91933

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.

EPSS

Процентиль: 26%
0.00328
Низкий

7.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.1
github
3 дня назад

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.

EPSS

Процентиль: 26%
0.00328
Низкий

7.1 High

CVSS3

Дефекты

CWE-639