THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2364-jh4q-m9vm (medium) — Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

[GHSA] GHSA-2364-jh4q-m9vm (medium) — Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

highgithub_advisoriesPublished 2026-08-04

GHSA-2364-jh4q-m9vm Severity: medium CVE: None

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

### Summary An Insecure Direct Object Reference (IDOR) vulnerability exists at the **GET /api/v1/organization/customer-default-source** endpoint. This flaw allows an authenticated attacker to bypass authorization checks and retrieve sensitive payment

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2364-jh4q-m9vm