GHSA-chm3-vqcf-52rx: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
Summary
Flowise has a cross-workspace credential vulnerability where attackers can access other users' OpenAI API keys if they know the credential ID. The server doesn't check whether credentials belong to the attacker's workspace before using them, allowing unauthorized access to victim OpenAI accounts and vector stores (collections of data used for AI search and retrieval).
Vulnerability Details
EPSS: 0.0%
Yes
August 4, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-chm3-vqcf-52rx
First tracked: August 4, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%