THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70473 (HIGH 8.5) — Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response

[NVD] CVE-2026-70473 (HIGH 8.5) — Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response

lownvdPublished 2026-08-04

CVE-2026-70473 CVSS: 8.5 HIGH Published: 2026-08-04T19:16:54.830

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70473