CVE-2026-100610 Overview
CVE-2026-100610 is a missing authorization vulnerability [CWE-639] in Flowise through version 3.1.4. The flaw affects two upsert-history endpoints that lack route-level permission checks and workspace or ownership validation. Any authenticated low-privilege user or holder of a valid API key can read or delete document-store upsert history belonging to other users and workspaces. Exploitation requires knowledge of a chatflowId, which Flowise exposes publicly in /chatbot/<chatflowId> share links. The retrievable flowData and result fields contain embedding, record-manager, and vector-store node configuration, including per-node paramValues. No patched version is available at the time of publication.
Critical Impact
Authenticated attackers can read sensitive AI pipeline configuration and delete upsert history across tenant boundaries, exposing embedding keys and vector-store credentials.
Affected Products
- Flowise versions up to and including 3.1.4
- Flowise GET /api/v1/upsert-history/:id endpoint
- Flowise PATCH /api/v1/upsert-history endpoint
Discovery Timeline
- 2026-09-26 - CVE-2026-100610 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100610
Vulnerability Analysis
Flowise exposes two REST endpoints that handle document-store upsert history records. The GET /api/v1/upsert-history/:id route invokes getAllUpsertHistory(), which returns UpsertHistory rows selected solely by an attacker-supplied chatflowid. The PATCH /api/v1/upsert-history route invokes patchDeleteUpsertHistory(), which deletes rows identified by an attacker-supplied array of record UUIDs.
Neither route enforces workspace membership, ownership, or role-based access control. An authenticated low-privilege user, including API-key holders, can query or delete upsert history belonging to other tenants. The returned flowData and result payloads expose configuration for embedding providers, record managers, and vector stores, including per-node paramValues such as API keys and connection strings.
Root Cause
The root cause is a broken access control pattern [CWE-639] where object references are trusted without server-side authorization. The controller layer performs no permission check, and the service layer queries the database using only the client-supplied identifier. This design assumes chatflowId and record UUIDs are secret, but chatflowId values are published in /chatbot/<chatflowId> share links.
Attack Vector
An attacker authenticates to Flowise using a low-privilege account or valid API key. The attacker then harvests a target chatflowId from any public /chatbot/<chatflowId> share link belonging to another workspace. Issuing GET /api/v1/upsert-history/<chatflowId> returns all upsert history rows for that chatflow, including embedded credentials. Alternatively, PATCH /api/v1/upsert-history with a crafted UUID array deletes arbitrary history rows across tenants.
See the GitHub Security Advisory GHSA-jvx3-mjpw-r4gh and the VulnCheck Advisory for Flowise for additional technical context.
Detection Methods for CVE-2026-100610
Indicators of Compromise
- Requests to GET /api/v1/upsert-history/:id where the chatflowid parameter does not belong to the authenticated principal's workspace
- PATCH /api/v1/upsert-history requests containing UUID arrays referencing rows outside the caller's workspace
- Spikes in upsert-history row deletions correlated to a single API key or low-privilege user
- Access from API keys to chatflows they have never previously interacted with
Detection Strategies
- Enable verbose HTTP access logging on the Flowise API and correlate chatflowid values with workspace ownership records
- Alert when a single principal queries upsert history for more than one chatflow within a short time window
- Compare the authenticated user's workspace membership against the owning workspace of every requested chatflowid
Monitoring Recommendations
- Forward Flowise reverse-proxy logs into a centralized analytics pipeline and retain request paths and authenticated identity
- Monitor outbound traffic from embedding and vector-store providers for credential reuse originating outside the Flowise host
- Rotate and audit all API keys periodically and track their last-used chatflow identifiers
How to Mitigate CVE-2026-100610
Immediate Actions Required
- Restrict network access to the Flowise API to trusted administrators until a patch is released
- Revoke and reissue API keys that may have been exposed in upsert-history flowData or result fields
- Rotate credentials for all embedding providers, record managers, and vector stores referenced in affected chatflows
- Treat all chatflowId values embedded in /chatbot/<chatflowId> share links as public and audit historical exposure
Patch Information
No patched version of Flowise is available at the time of publication. Monitor the FlowiseAI GitHub repository for a fixed release.
Workarounds
- Deploy a reverse proxy or API gateway in front of Flowise that enforces per-workspace authorization on /api/v1/upsert-history/* routes
- Disable public chatbot share links so chatflowId values are not disclosed to unauthenticated users
- Limit API-key issuance to the smallest set of users who require programmatic access and scope keys to specific chatflows where possible
- Isolate multi-tenant Flowise deployments into dedicated instances per workspace until authorization is enforced upstream
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.