In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade flowise to version 3.1.3 or higher.
flowise is a Flowiseai Server
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the customerId parameter in the GET /api/v1/organization/customer-default-source endpoint. An attacker can access sensitive payment and profile information of other users by manipulating this parameter to reference arbitrary customer IDs while authenticated.