NPM · AUGUST 2026 · EARLY WARNING

Flowise <=3.1.4 Insecure Direct Object Reference Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-67622Severity: CRITICAL

Flowise versions up to and including 3.1.4 appear to have an insecure direct object reference vulnerability in the OpenAI Assistants integration, potentially allowing authenticated attackers to access credentials belonging to other workspaces.

What happened

Flowise through version 3.1.4 is under investigation for an insecure direct object reference vulnerability in its OpenAI Assistants integration. This vulnerability, tracked as CVE-2026-67622, reportedly allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without proper workspace ownership verification. Attackers may be able to enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic. The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.9. It is recommended to upgrade to a patched version of Flowise once available and rotate any affected credentials. For more details, consult the primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If flowise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats