THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p5w8-m249-4r4v (high) — Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type

[GHSA] GHSA-p5w8-m249-4r4v (high) — Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type

medgithub_advisoriesPublished 2026-08-04

GHSA-p5w8-m249-4r4v Severity: high CVE: CVE-2026-69262

Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type

# summary: In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p5w8-m249-4r4v