CVE-2026-100609

CVE-2026-100609 published: Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in several code paths: getAllOpenaiAssist...

View full NVD advisory → ← Back to CVE watch