๐Ÿ” CVE Alert

CVE-2026-73488

UNKNOWN 0.0

Flowise before 3.1.3 IDOR via customer-default-source endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks.

CWE CWE-639
Vendor flowiseai
Product flowise
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for flowiseai flowise

Be the first to know when new unknown vulnerabilities affecting flowiseai flowise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FlowiseAI / Flowise
0 < 3.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-2364-jh4q-m9vm vulncheck.com: https://www.vulncheck.com/advisories/flowise-before-idor-via-customer-default-source-endpoint

Credits

๐Ÿ” truongvip1