Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cwc3-p92j-g7qm | Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 07 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13. | |
| Title | Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-07T05:10:08.035Z
Reserved: 2026-03-05T21:06:44.605Z
Link: CVE-2026-30823
No data.
Status : Received
Published: 2026-03-07T06:16:10.007
Modified: 2026-03-07T06:16:10.007
Link: CVE-2026-30823
No data.
OpenCVE Enrichment
No data.
Github GHSA