What happened
NVD/GitHub advisory (GHSA-jvx3-mjpw-r4gh, CVSS 7.5, published 2026-09-26) documents that Flowise upsert-history routes carry no permission or workspace checks, enabling cross-workspace disclosure and deletion of document-store upsert history even when the target chatflow is only publicly shared, not exported.
Why it matters
In a multi-tenant Flowise deployment the RAG/vector-store configuration and parsed embeddings data of other tenants' AI agents can be enumerated and destroyed by a low-privilege user or leaked API key — a tenant-isolation break on the agentic retrieval layer. Upgrade to the fixed Flowise release and do not rely on chatflowId secrecy.
Attack vector
GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history lack route-level permission checks and the service queries/deletes rows only by attacker-supplied chatflowid/UUID. Public shared-chatbot links (/chatbot/<chatflowId>) expose valid global chatflow IDs, so an attacker in another workspace can retrieve the victim's UpsertHistory — which stores parsed results and flowData snapshots containing embedding/record-manager/vector-store node configs (paramValues) — and delete history rows.
Mitigation
Upgrade Flowise to the patched release that adds permission/workspace checks on the upsert-history routes; advisory: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jvx3-mjpw-r4gh