THREAT OPS › Threat News › [GHSA] GHSA-chm3-vqcf-52rx (high) — Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
[GHSA] GHSA-chm3-vqcf-52rx (high) — Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
GHSA-chm3-vqcf-52rx Severity: high CVE: CVE-2026-70472
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
# Summary
These endpoints accept a client-controlled `credential` parameter. The server loads credentials by `id` and uses them directly, without checking whether that credential belongs to the caller’s workspace. If an attacker knows another workspace’s `credential
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-70472cve
Original source: https://github.com/advisories/GHSA-chm3-vqcf-52rx