CVE-2026-71962: fallo de gravedad alta en FlowiseAI Flowise
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
Publicada el · Actualizada el
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 8.7epss 0.7%
probabilidad de explotación
0.7%top 49% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
FlowiseAI · FlowisePoCs públicas encontradas — 1
cve_referencegist.github.com/haidang-infosec/402db84bee7aca2f57bb109b31574649?utm_source=chatgpt.comno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — FlowiseAI Flowise
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-59528CRITICALFlowise has Remote Code Execution vulnerabilityEPSS 86.2%CVE-2025-58434CRITICALFlowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account TakeoverEPSS 49.9%CVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2025-50538HIGHCVE-2025-50538EPSS 14.0%CVE-2024-8182HIGHFlowise Denial of ServiceEPSS 13.9%CVE-2025-61913CRITICALFlowise is vulnerable to arbitrary file read, arbitrary file writeEPSS 13.0%