| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cwc3-p92j-g7qm | Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 11 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* |
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Vendors & Products |
Flowiseai
Flowiseai flowise |
Sat, 07 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13. | |
| Title | Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T20:44:24.602Z
Reserved: 2026-03-05T21:06:44.605Z
Link: CVE-2026-30823
Updated: 2026-03-09T20:35:38.393Z
Status : Analyzed
Published: 2026-03-07T06:16:10.007
Modified: 2026-03-11T13:36:25.867
Link: CVE-2026-30823
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:05:56Z
Github GHSA