CVE-2026-100609: Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on
Summary
Flowise (a workflow automation tool available as npm packages) versions up to 3.1.4 has a security flaw where it retrieves stored credentials (like API keys) by ID without checking if the user requesting them belongs to the correct workspace (a group or project within the system). An authenticated attacker can use this flaw to access and decrypt API keys from other workspaces by providing their credential IDs, potentially gaining unauthorized access to external services like OpenAI or ElevenLabs.
Vulnerability Details
6.8(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
network
high
low
none
September 26, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-100609
First tracked: September 26, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%