Skip to content
FlowiseGHSA-p5w8-m249-4r4v

Flowise: improper authorization

HighCVE-2026-69262 · Published Aug 4, 2026

# summary: In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource `type`, allowing a caller with only `agentflows:delete` to delete a `CHATFLOW`, and a caller with only `chatflows:delete` to delete an `AGENTFLOW`. # details: The delete route accepts either `chatflows:delete` or `agentflows:delete`. The subsequent logic only resolves the target record by `id` and `workspaceId`, then deletes by `id` without checking whether the target resource type matches the granted permission domain. As a result, there is no binding between permission scope and flow type: - `agentflows:delete` can be used to delete `CHATFLOW` - `chatflows:delete` can be used to delete `AGENTFLOW` This breaks the intended RBAC separation between Chatflows and Agentflows. # impact: Users authorized to manage only one flow type can delete the other flow type within the same workspace, resulting in unauthorized deletion and configuration loss. # reproduction steps: 1. Log in as a user who can create API keys. 2. Cr...

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
< 3.1.33.1.3
Details and references

# summary: In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource `type`, allowing a caller with only `agentflows:delete` to delete a `CHATFLOW`, and a caller with only `chatflows:delete` to delete an `AGENTFLOW`. # details: The delete route accepts either `chatflows:delete` or `agentflows:delete`. The subsequent logic only resolves the target record by `id` and `workspaceId`, then deletes by `id` without checking whether the target resource type matches the granted permission domain. As a result, there is no binding between permission scope and flow type: - `agentflows:delete` can be used to delete `CHATFLOW` - `chatflows:delete` can be used to delete `AGENTFLOW` This breaks the intended RBAC separation between Chatflows and Agentflows. # impact: Users authorized to manage only one flow type can delete the other flow type within the same workspace, resulting in unauthorized deletion and configuration loss. # reproduction steps: 1. Log in as a user who can create API keys. 2. Create a normal `CHATFLOW` and record its `id`. 3. Create an API key with only `agentflows:delete`. 4. Use that API key to send: ```bash curl -i -X DELETE \ -H 'Authorization: Bearer <agentflows_delete_only_key>' \ http://localhost:8080/api/v1/chatflows/<chatflow_id> ``` 5. Observe a `200 OK` response, for example: ```json {"raw":[],"affected":1} ``` 6. Read the same `id` again and observe `404 Not Found`.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
CVE-2026-69262

More Flowise advisories

All Flowise

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.