---
id: CVE-2026-91933
title: >-
  Flowise before 3.1.4 fails to enforce workspace-level authorization checks in
  openai-realtime endpoints, allowing authenticated users to access tools from
  ChatFlows in other workspaces by supplying an unscoped chatflowid
summary: >-
  Flowise before 3.1.4 fails to enforce workspace-level authorization checks in
  openai-realtime endpoints, allowing authenticated users to access tools from
  ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers
  can i…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-639
vendor: FlowiseAI
product: Flowise
affected:
  - Flowise < 3.1.4
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T20:18:53.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91933'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gggp-6qmf-xwwc
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-before-3.1.4-authorization-bypass-via-openai-realtime
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T18:57:09.710464Z'
epss: 0.00352
epssPercentile: 0.26157
ingestedAt: '2026-09-15T15:39:12.925Z'
---

## Overview

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
