THREAT OPS › Threat News › [GHSA] GHSA-fr6g-7cq8-fg82 (high) — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
[GHSA] GHSA-fr6g-7cq8-fg82 (high) — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
GHSA-fr6g-7cq8-fg82 Severity: high CVE: CVE-2026-70473
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
### Summary The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace. The response includes **sensitive c
Indicators of compromise
- CVE-2026-70473cve
- https://7f60f255-f7fd-4a1c-a734-fbcf904f9f85.europe-west3-0.gcp.cloud.qdrant.iourl
- https://cloud.flowiseai.com/api/v1/upsert-historyurl
- https://cloud.flowiseai.com/document-stores/vector/27d7e649-72c9-4333-836f-0a32b7ecda57/719bc75c-5810-4d22-aa03-35c7831b8819url
- 1.2.1.1ipv4
- 1.0.1.1ipv4
Original source: https://github.com/advisories/GHSA-fr6g-7cq8-fg82