{"data":{"id":"7878aaee-7d60-4d7e-be81-bdf6735cea8e","title":"CVE-2026-100609: Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on ","summary":"Flowise (a workflow automation tool available as npm packages) versions up to 3.1.4 has a security flaw where it retrieves stored credentials (like API keys) by ID without checking if the user requesting them belongs to the correct workspace (a group or project within the system). An authenticated attacker can use this flaw to access and decrypt API keys from other workspaces by providing their credential IDs, potentially gaining unauthorized access to external services like OpenAI or ElevenLabs.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100609","publishedAt":"2026-09-26T14:16:41.297Z","cveId":"CVE-2026-100609","cweIds":["CWE-639"],"cvssScore":"6.8","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["Flowise","OpenAI","ElevenLabs"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:41.297Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}