ZeroHour

CVE-2026-30823

PoC
CVSS 3.0
8.8 high
EPSS
<1%p38
Published
()
Modified
Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.

Vendors
flowiseai
Products
flowise
Weakness
CWE-639, CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.