HIGH GitHub

CVE-2026-70471

Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view) ### What’s wrong (code locations) - Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/ packages/components/src/utils.ts:932 - Runtime variables are resolved from server environment variables: flowise-src/packages/components/src/utils.ts:976 - $vars is always injected into the code execution sandbox: flowise-src/packages

Affected Products

References

Published: 2026-08-04 · Source: GitHub · Feed updated: 2026-08-04
This high severity vulnerability was published on 2026-08-04 via GitHub. Affected: npm/flowise <= 3.1.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.