Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime variables are resolved from server environment variables, while the official variables route enforces variables:view. A user or API key that is denied variables:view can call /api/v1/node-custom-function and receive $vars pre-populated with all variables for the workspace, including Variable.name to Variable.value static variables and Variable.name to process.env[Variable.name] runtime variables. This can expose secrets such as database passwords, JWT secrets, SMTP passwords, and cloud keys, depending on the workspace Variables configuration. This issue is fixed in version 3.1.3.
References
| Link | Resource |
|---|---|
| https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3 | Issue Tracking Patch |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8r8h-6vcc-xhrv | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-04 19:16
Updated : 2026-09-14 19:09
NVD link : CVE-2026-70471
Mitre link : CVE-2026-70471
CVE.ORG link : CVE-2026-70471
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-863
Incorrect Authorization
