CVE-2026-73488 | FlowiseAI Flowise up to 3.1.2 customer-default-source customerId resource injection
A vulnerability labeled as problematic has been found in FlowiseAI Flowise up to 3.1.2. Affected by this vulnerability is an unknown functionality of the file /api/v1/organization/customer-default-source. Such manipulation of the argument customerId leads to improper control of resource identifiers.
This vulnerability is listed as CVE-2026-73488. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More