CVE-2026-30820
EUVD-2026-1010707.03.2026, 05:16
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the header x-request-from: internal, allowing an authenticated tenant session to bypass all /api/v1/** authorization checks. With only a browser cookie, a low-privilege tenant can invoke internal administration endpoints (API key management, credential stores, custom function execution, etc.), effectively escalating privilege. This issue has been patched in version 3.0.13.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flowiseai | flowise | 𝑥 < 3.0.13 |
𝑥
= Vulnerable software versions