THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8r8h-6vcc-xhrv (high) — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

[GHSA] GHSA-8r8h-6vcc-xhrv (high) — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

medgithub_advisoriesPublished 2026-08-04

GHSA-8r8h-6vcc-xhrv Severity: high CVE: CVE-2026-70471

Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)

### What’s wrong (code locations)

- Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/ packa

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8r8h-6vcc-xhrv