CVE-2026-30823

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-07 06:16

Updated : 2026-03-11 13:36


NVD link : CVE-2026-30823

Mitre link : CVE-2026-30823

CVE.ORG link : CVE-2026-30823


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-862

Missing Authorization