CyberRota Analysis
AI-GeneratedFlowise versions prior to 3.1.4 are vulnerable to cross-tenant authorization gaps in Enterprise endpoints, allowing attackers with Enterprise access to manipulate resources across different organizations. This includes the ability to delete arbitrary workspaces, invite themselves into other organizations, modify cross-organization roles, and exploit stored SSO secrets. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.