HIGH 7.5 NVD
CVE-2026-100605
Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Att
Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages.
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-ppmg-4cx6-95hh
- https://www.vulncheck.com/advisories/flowise-through-3.1.4-missing-authorization-via-chat-
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11675 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.