CVE-2026-73488 | FlowiseAI Flowise up to 3.1.2 customer-default-source customerId resource injection

SecurityVulns

A vulnerability labeled as problematic has been found in FlowiseAI Flowise up to 3.1.2. Affected by this vulnerability is an unknown functionality of the file /api/v1/organization/customer-default-source. Such manipulation of the argument customerId leads to improper control of resource identifiers.

This vulnerability is listed as CVE-2026-73488. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More