THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wp74-f5hh-5f3r (high) — Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization

[GHSA] GHSA-wp74-f5hh-5f3r (high) — Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization

medgithub_advisoriesPublished 2026-08-04

GHSA-wp74-f5hh-5f3r Severity: high CVE: CVE-2026-69252

Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization

# summary: In Flowise, the `/api/v1/files` route is protected only by the `feat:files` feature gate and does not enforce `checkPermission(...)` on either `GET` or `DELETE`. As a result, any

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wp74-f5hh-5f3r