THREAT OPS › Threat News › [GHSA] GHSA-8r8h-6vcc-xhrv (high) — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
[GHSA] GHSA-8r8h-6vcc-xhrv (high) — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
GHSA-8r8h-6vcc-xhrv Severity: high CVE: CVE-2026-70471
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)
### What’s wrong (code locations)
- Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/ packa
Indicators of compromise
- CVE-2026-70471cve
Original source: https://github.com/advisories/GHSA-8r8h-6vcc-xhrv