CVE-2026-100610

CVE-2026-100610 published: Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows sele...

View full NVD advisory → ← Back to CVE watch