THREAT OPS › Threat News › [GHSA] GHSA-p5w8-m249-4r4v (high) — Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
[GHSA] GHSA-p5w8-m249-4r4v (high) — Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
GHSA-p5w8-m249-4r4v Severity: high CVE: CVE-2026-69262
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
# summary: In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient
Indicators of compromise
- CVE-2026-69262cve
Original source: https://github.com/advisories/GHSA-p5w8-m249-4r4v