GitHub Security Advisory (GHSA-2364-jh4q-m9vm)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-2364-jh4q-m9vm CVE-2026-73488
MEDIUM
Flowise before 3.1.3 IDOR via customer-default-source endpoint
Record summary
CVE-2026-73488 has a selected CVSS score of 6.0 (medium).
Description
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.3 | affected |
| 3.1.3 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73488 VulnCheck Advisory: Flowise before 3.1.3 IDOR via customer-default-source endpointThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-idor-via-customer-default-source-endpoint