PoC Index

CVE-2026-30823

HIGH 8.8EPSS 0.4%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.45% chance of exploitation in the next 30 days, 37th percentile
Published
2026-03-07
Updated
2026-03-09

Proof-of-concept exploits (1)

References

Related