CVE-2026-100605 Overview
CVE-2026-100605 is a missing authorization vulnerability [CWE-862] in Flowise through version 3.1.4. The flaw affects chat message endpoints that lack route-level role-based access control (RBAC) checks. Low-privileged API keys can read and delete chat history without the required flow permissions. Attackers can access GET and DELETE chat message routes to retrieve chat histories, prompts, model responses, and remove messages.
Flowise is an open-source platform used to build large language model (LLM) orchestration workflows. The missing authorization controls expose sensitive conversational data and allow destructive actions against stored chat records.
Critical Impact
Low-privileged API keys can read full chat histories, including user prompts and model responses, and delete chat messages across flows they should not control.
Affected Products
- Flowise versions up to and including 3.1.4
- FlowiseAI self-hosted deployments exposing the chat message API
- Any integration relying on Flowise API keys for tenant or flow isolation
Discovery Timeline
- 2026-09-26 - CVE-2026-100605 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100605
Vulnerability Analysis
The vulnerability stems from missing authorization checks on chat message routes in the Flowise HTTP API. The affected endpoints validate that an API key is present and valid but do not verify that the key holds the required flow-level permissions. As a result, any authenticated key, regardless of scope, can invoke GET and DELETE operations against chat message resources.
Successful exploitation exposes conversational data that often contains proprietary prompts, retrieved context from retrieval-augmented generation (RAG) pipelines, personally identifiable information (PII), and model responses. The DELETE path additionally enables tampering and loss of audit history, which can obstruct incident response and compliance recordkeeping.
The attack is network-based and requires low privileges. User interaction is marked as passive in the CVSS 4.0 vector. Confidentiality, integrity, and availability impacts on the vulnerable system are all rated high.
Root Cause
Flowise applies authentication at the API gateway layer but omits per-route authorization enforcement for chat message endpoints. The flow permission model exists for other endpoints but is not consistently applied to chat history read and delete handlers. This gap is a textbook instance of CWE-862: Missing Authorization.
Attack Vector
An attacker who obtains or is issued a low-privileged API key, including a key scoped to an unrelated flow, can issue HTTP requests directly to the chat message routes. The server returns chat histories and executes deletions without validating ownership or flow membership. No user interaction with the Flowise UI is required beyond issuing authenticated API calls.
The vulnerability is described in the GitHub Security Advisory GHSA-ppmg-4cx6-95hh and the VulnCheck Advisory for Flowise 3.1.4.
Detection Methods for CVE-2026-100605
Indicators of Compromise
- Unexpected GET requests to chat message endpoints from API keys that do not own the targeted flow
- DELETE requests to chat message routes correlated with low-privileged API key identifiers
- Spikes in chat history read volume from a single API key across multiple chatflowid values
- Missing or truncated chat history records without a corresponding administrative action
Detection Strategies
- Enable verbose API access logging in Flowise and ship logs to a centralized analytics platform
- Build detections that correlate API key identity with the chatflowid parameter and alert on cross-flow access
- Baseline normal chat message read and delete activity per API key and flag deviations
Monitoring Recommendations
- Monitor HTTP 200 responses on chat message GET routes paired with keys that lack owner scope
- Track DELETE operations on chat message routes and require ticketed justification for each
- Alert on API key enumeration patterns iterating through sequential chatflowid or chat message identifiers
How to Mitigate CVE-2026-100605
Immediate Actions Required
- Upgrade Flowise to a version later than 3.1.4 that enforces route-level RBAC on chat message endpoints
- Rotate all Flowise API keys and reissue them with least-privilege scope
- Restrict network exposure of the Flowise API to trusted clients using an authenticating reverse proxy
- Audit chat history for evidence of unauthorized read or delete activity
Patch Information
Review the FlowiseAI security advisory GHSA-ppmg-4cx6-95hh for the fixed version and remediation guidance. Apply the vendor-released update that adds flow permission checks to chat message routes.
Workarounds
- Place Flowise behind a reverse proxy that enforces authorization on /api/v1/chatmessage routes based on key scope
- Disable or revoke low-privileged API keys that do not require chat history access
- Segment Flowise instances per tenant or flow owner to limit blast radius until the patch is applied
# Example NGINX restriction blocking chat message routes from non-admin API keys
location ~ ^/api/v1/chatmessage {
if ($http_authorization !~* "Bearer ADMIN_KEY_PREFIX_") {
return 403;
}
proxy_pass http://flowise_upstream;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.