CVE-2026-70473

HIGH CVSS 4.0: 8.3 EPSS 0.25%
Updated Aug 04, 2026
Flowiseai
Parameter Value
CVSS 8.3 (HIGH)
Fixed In 3.1.3
Type CWE-202, CWE-862 (Missing Authorization), CWE-200 (Information Exposure)
Vendor Flowiseai
Public PoC No

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name.

The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products

flowiseai:flowise