Feed/CVE-2026-69262
CVE-2026-69262HIGHCVSS 0.0

Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type

Published Aug 4, 2026·Updated Aug 4, 2026

NVD Description

# summary: In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource `type`, allowing a caller with only `agentflows:delete` to delete a `CHATFLOW`, and a caller with only `chatflows:delete` to delete an `AGENTFLOW`. # details: The delete route accepts either `chatflows:delete` or `agentflows:delete`. The subsequent logic only resolves the target record by `id` and `workspaceId`, then deletes by `id` without checking whether the target resource type matches the granted permission domain. As a result, there is no binding between permission scope and flow type: - `agentflows:delete` can be used to delete `CHATFLOW` - `chatflows:delete` can be used to delete `AGENTFLOW` This breaks the intended RBAC separation between Chatflows and Agentflows. # impact: Users authorized to manage only one flow type can delete the other flow type within the same workspace, resulting in unauthorized deletion and configuration loss. # reproduction steps: 1. Log in as a user who can create API keys. 2. Create a normal `CHATFLOW` and record its `id`. 3. Create an API key with only `agentflows:delete`. 4. Use that API key to send: ```bash curl -i -X DELETE \ -H 'Authorization: Bearer <agentflows_delete_only_key>' \ http://localhost:8080/api/v1/chatflows/<chatflow_id> ``` 5. Observe a `200 OK` response, for example: ```json {"raw":[],"affected":1} ``` 6. Read the same `id` again and observe `404 Not Found`.

Affected Packages (1)

flowiseNPM
Fixed in = 3.1.2

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free