MODERATEnpm

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

CVE-2026-73488Published 4 weeks agoUpdated 3 weeks agoSource: OSV

Affected packages

  • flowise

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint | HackTribune