THREAT OPS › Threat News › [GHSA] GHSA-wp74-f5hh-5f3r (high) — Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
[GHSA] GHSA-wp74-f5hh-5f3r (high) — Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
GHSA-wp74-f5hh-5f3r Severity: high CVE: CVE-2026-69252
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
# summary: In Flowise, the `/api/v1/files` route is protected only by the `feat:files` feature gate and does not enforce `checkPermission(...)` on either `GET` or `DELETE`. As a result, any
Indicators of compromise
- CVE-2026-69252cve
Original source: https://github.com/advisories/GHSA-wp74-f5hh-5f3r