THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fr6g-7cq8-fg82 (high) — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

[GHSA] GHSA-fr6g-7cq8-fg82 (high) — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

highgithub_advisoriesPublished 2026-08-04

GHSA-fr6g-7cq8-fg82 Severity: high CVE: CVE-2026-70473

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

### Summary The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace. The response includes **sensitive c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fr6g-7cq8-fg82