Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Vendors & Products |
Flowiseai
Flowiseai flowise |
Sat, 07 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13. | |
| Title | Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-07T05:10:08.035Z
Updated: 2026-03-07T05:10:08.035Z
Reserved: 2026-03-05T21:06:44.605Z
Link: CVE-2026-30823
No data.
Status : Awaiting Analysis
Published: 2026-03-07T06:16:10.007
Modified: 2026-03-09T13:35:34.633
Link: CVE-2026-30823
No data.