CVE-2026-30823

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

11 Mar 2026, 13:36

Type Values Removed Values Added
First Time Flowiseai
Flowiseai flowise
CPE cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
References () https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.13 - () https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.13 - Product, Release Notes
References () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-cwc3-p92j-g7qm - () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-cwc3-p92j-g7qm - Exploit, Vendor Advisory
Summary
  • (es) Flowise es una interfaz de usuario de arrastrar y soltar para construir un flujo de modelo de lenguaje grande personalizado. Antes de la versión 3.0.13, existe una vulnerabilidad IDOR, que conduce a la toma de control de cuentas y a la elusión de funciones empresariales a través de la configuración de SSO. Este problema ha sido parcheado en la versión 3.0.13.

07 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 06:16

Updated : 2026-03-11 13:36


NVD link : CVE-2026-30823

Mitre link : CVE-2026-30823

CVE.ORG link : CVE-2026-30823


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-862

Missing Authorization