Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100606— Flowise through 3.1.4 Authentication Bypass via SSO Email Match

Quick assessment

Affected
FlowiseAI Flowise
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Flowise 3.1.4 版本(启用 SSO 的企业版/平台模式)在 SSO 登录路径中存在身份验证绕过漏洞。当收到一个 SSO 回调请求,其携带的电子邮件地址匹配状态为“已邀请”(INVITED)的用户时, 函数(位于 SSOBase.ts 第 80–94 行)会从数据库中复制该用户记录——包括服务器端存储的单次使用邀请临时令牌(tempToken)——并将这些数据传递给 。由于注册处理程序中的令牌查找、邮箱匹配和过期检查均基于服务器自身存储的令牌而非调用方提供的令牌,因此这些检查被轻易绕过,从而使该用户账户及

CVSS 7.7 · High EPSS 0.37% · P29

Affected Version Matrix 1

VendorProduct Version RangeStatus
FlowiseAI Flowise ≤ 3.1.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100606

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Flowise through 3.1.4 Authentication Bypass via SSO Email Match
Source: CVE Program / CVE List V5
Vulnerability Description
Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored single-use invitation tempToken — into the data passed to AccountService.register(). The register handler's token lookup, email match, and expiry checks therefore pass trivially against the server's own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee's email address as the email claim can take over that invitation and obtain the invited user's access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FlowiseAI Flowise 0 ~ 3.1.4 -

II. Public POCs for CVE-2026-100606

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100606

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100606 (2)

Same Patch Batch · FlowiseAI · 2026-09-26 · 6 CVEs total

CVE-2026-100608 8.3 HIGH Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard
CVE-2026-100607 7.7 HIGH Flowise through 3.1.4 Authentication Bypass via Email-Only SSO
CVE-2026-100610 7.5 HIGH Flowise through 3.1.4 Missing Authorization via upsert-history
CVE-2026-100605 7.1 HIGH Flowise through 3.1.4 Missing Authorization via Chat Message Routes
CVE-2026-100609 6.8 MEDIUM Flowise through 3.1.4 Insecure Direct Object Reference via Credential

IV. Related Vulnerabilities

V. Comments for CVE-2026-100606

No comments yet


Leave a comment