What is CVE-2026-70473?
CVE-2026-70473 is a critical data leakage vulnerability in the Flowise platform. In versions prior to 3.1.3, the /api/v1/upsert-history endpoint returns the entire server-wide upsert history instead of scoping it to the requesting user, potentially exposing sensitive data exceeding 100MB. Users should immediately upgrade to Flowise version 3.1.3 or later.
Azərbaycanca: CVE-2026-70473 Flowise platformasında aşkarlanmış kritik məlumat sızması boşluğudur. 3.1.3 versiyasından əvvəlki versiyalarda /api/v1/upsert-history endpoint-i sorğu göndərən istifadəçinin əhatə dairəsi ilə məhdudlaşmır və bütün server üzrə yükləmə tarixçəsini ifşa edir. İstifadəçilər dərhal Flowise-i 3.1.3 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What issue does CVE-2026-70473 cause in the Flowise platform?
Due to the /api/v1/upsert-history endpoint not scoping to the requesting user, this vulnerability exposes the entire server-wide upsert history, potentially leaking sensitive data exceeding 100MB.
To which version should users upgrade to mitigate CVE-2026-70473?
Users should upgrade to Flowise version 3.1.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.