Vulnerabilities · 75 days ago

Flowise Session Cookies Can Be Forged

Flowise is treating session cookies as the trust boundary, so a forged cookie can make the site accept an attacker as a logged-in user. That turns authentication bypass into account impersonation inside any deployment that relies on Flowise access controls. CSIRT Italia says the flaw affects Flowise versions before 3.1.0 and recommends upgrading to 3.1.0.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-07-01

Editions

Related stories