CyberRota Analysis
AI-GeneratedVersions of Flowise prior to 3.1.3 are vulnerable to an insecure direct object reference in the API endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. This vulnerability can lead to unauthorized exposure of sensitive information, such as email addresses and account balances. Organizations using affected versions should prioritize patching to mitigate the risk of data breaches and protect customer privacy.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks.