Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs. | |
| Title | Flowise before 3.1.4 Authorization Bypass via openai-realtime | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T19:28:56.360Z
Reserved: 2026-09-15T11:06:02.263Z
Link: CVE-2026-91933
Updated: 2026-09-17T18:57:11.642Z
Status : Awaiting Analysis
Published: 2026-09-15T16:17:44.170
Modified: 2026-09-17T20:18:53.830
Link: CVE-2026-91933
No data.
OpenCVE Enrichment
Updated: 2026-09-17T15:30:20Z
-
CWE-639
Authorization Bypass Through User-Controlled Key