Flowise is treating session cookies as the trust boundary, so a forged cookie can make the site accept an attacker as a logged-in user. That turns authentication bypass into account impersonation inside any deployment that relies on Flowise access controls. CSIRT Italia says the flaw affects Flowise versions before 3.1.0 and recommends upgrading to 3.1.0.
Part of the PlainSec briefing for 2026-07-01