HIGH GitHub
CVE-2026-70471
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)
### What’s wrong (code locations)
- Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/
packages/components/src/utils.ts:932
- Runtime variables are resolved from server environment variables: flowise-src/packages/components/src/utils.ts:976
- $vars is always injected into the code execution sandbox: flowise-src/packages
Affected Products
- npm/flowise <= 3.1.2
References
- https://github.com/advisories/GHSA-8r8h-6vcc-xhrv
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8r8h-6vcc-xhrv
- https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3
- https://github.com/advisories/GHSA-8r8h-6vcc-xhrv
This high severity vulnerability was published on 2026-08-04 via GitHub. Affected: npm/flowise <= 3.1.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.