Threat Advisory

Flowise Vulnerabilities Enable Authorization Bypass and Privilege Escalation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Several vulnerabilities have been identified in Flowise affecting versions up to 3.0.12 that could allow attackers to bypass authorization controls access privileged functionality upload malicious files and manipulate application data. One issue allows attackers to bypass API authorization checks by spoofing a specific request header which may enable low privilege users to access internal administrative features and escalate privileges. Another vulnerability allows arbitrary file uploads because the application relies on the client provided MIME type without validating the actual file content which can allow malicious files to be stored in backend systems. Additional weaknesses allow attackers to modify internal fields through improper input handling in a data submission endpoint and exploit an object reference flaw to modify authentication configuration belonging to other organizations leading to possible account takeover and unauthorized feature activation. A separate issue also exposes certain container management related endpoints without authentication allowing unauthorized access to sensitive functionality.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Several vulnerabilities have been identified in Flowise affecting versions up to 3.0.12 that could allow attackers to bypass authorization controls access privileged functionality upload malicious files and manipulate application data. One issue allows attackers to bypass API authorization checks by spoofing a specific request header which may enable low privilege users to access internal administrative features and escalate privileges. Another vulnerability allows arbitrary file uploads because the application relies on the client provided MIME type without validating the actual file content which can allow malicious files to be stored in backend systems. Additional weaknesses allow attackers to modify internal fields through improper input handling in a data submission endpoint and exploit an object reference flaw to modify authentication configuration belonging to other organizations leading to possible account takeover and unauthorized feature activation. A separate issue also exposes certain container management related endpoints without authentication allowing unauthorized access to sensitive functionality.[emaillocker id="1283"]

 

  • CVE-2026-30820 – This vulnerability has a CVSS score of 8.7 and allows an authorization bypass due to the application trusting a spoofed x-request-from header. By setting the header value to internal an authenticated low privilege user can bypass authorization checks on protected API routes and access internal administrative endpoints resulting in privilege escalation.

 

  • CVE-2026-30821 – This vulnerability has a CVSS score of 8.2 and allows arbitrary file upload because the system trusts the client supplied MIME type in the Content-Type header. Attackers can spoof allowed file types while uploading malicious files which may later be used for stored script execution malicious hosting or remote code execution.

 

  • CVE-2026-30822 – This vulnerability has a CVSS score of 7.7 and results from a mass assignment issue in the endpoint. The application copies all user supplied fields directly into internal objects without validation allowing attackers to modify protected attributes such as identifiers or timestamps and manipulate stored records.

 

  • CVE-2026-30823 – This vulnerability has a CVSS score of 8.8 and occurs due to improper object reference validation in the login configuration endpoint. Authenticated users can modify the configuration of other organizations leading to account takeover scenarios and unauthorized activation of enterprise authentication features.

 

  • CVE-2026-30824 – This vulnerability has a CVSS score of 8.6 and occurs because certain NVIDIA NIM related API endpoints are exposed without authentication checks. This allows unauthorized users to access privileged functionality related to container management and token generation.

 

These vulnerabilities expose Flowise deployments to privilege escalation unauthorized configuration changes and malicious file uploads through weaknesses in authorization validation and input handling. Updating to the patched version resolves these issues and prevents unauthorized access to sensitive API functionality.

RECOMMENDATION:

We strongly recommend update Flowise to version 3.0.13.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu