GHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks
highvulnerabilityLLM-Specific
security
Source: GitHub Advisory DatabaseMay 14, 2026
Summary
FlowiseAI's OpenAI Assistants Vector Store endpoints lack permission checks, allowing any authenticated user to create, modify, delete, or upload files to vector stores regardless of their assigned role. This missing authorization (CWE-306, a security weakness where critical functions don't verify user permissions) has a severity score of about 8.1, meaning attackers with basic access could steal or destroy data.
Classification
Attack SophisticationTrivial
Impact (CIA+S)
confidentialityintegrityavailability
Affected Vendors
OpenAI
Affected Packages
flowise@<= 3.1.1 (fixed: 3.1.2)
Related Issues
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-hmg2-jjjx-jcp2
First tracked: May 14, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%