Title
Missing RBAC checks on Flowise chat message routes allow low-privileged API keys to read and delete chat history
Description
Flowise flowise@3.1.2 appears to have missing route-level RBAC checks on chat message read/delete routes.
The global /api/v1 middleware validates API keys and assigns req.user.permissions = apiKey.permissions, but the affected chat message routes call their controllers directly without checkAnyPermission(...).
Affected files:
packages/server/src/routes/chat-messages/index.ts
packages/server/src/routes/internal-chat-messages/index.ts
Affected routes:
GET /api/v1/chatmessage/:id
GET /api/v1/internal-chatmessage/:id
DELETE /api/v1/chatmessage/:id
Confirmed affected release:
flowise@3.1.2
- tag commit
4114b3b506e7bbee155141175a2ba48e426919dd
Impact
A valid but low-privileged API key for a workspace can reach chat message read/delete handlers without having the expected flow permissions.
Potential impact:
- Read chat histories and internal test chat messages for known flow IDs.
- Access prompts, model responses, source documents, used tools, feedback, and uploaded file metadata serialized in chat messages.
- Delete chat messages and related uploaded files without flow delete permission.
Suggested CVSS v3.1:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Estimated severity: High, 8.3.
Affected versions
Confirmed:
Broader affected range:
- Unknown; maintainers should confirm whether earlier RBAC-enabled releases are also affected.
Reproduction steps
- Add the test file from the patch package to:
packages/server/src/routes/chat-messages/authorization.test.ts
- Before applying the route patch, run:
pnpm --dir packages/server exec jest src/routes/chat-messages/authorization.test.ts --runInBand
-
Observe insufficient-permission requests return 200 instead of 403.
-
Apply the route patch.
-
Run the same test again.
-
Observe insufficient-permission requests return 403, while requests with chatflows:view, agentflows:view, or agentflows:delete continue to succeed.
Safe PoC
The PoC is a Jest/supertest test with mocked controllers. It uses dummy data only and does not touch real users, credentials, or a database.
Pre-patch observed output:
FAIL src/routes/chat-messages/authorization.test.ts
Tests: 3 failed, 3 passed, 6 total
Expected: 403
Received: 200
Post-patch observed output:
PASS src/routes/chat-messages/authorization.test.ts
Tests: 6 passed, 6 total
I also reproduced the issue against a real local Flowise server with a dummy SQLite database:
Vulnerable local server:
GET /api/v1/chatmessage/:id -> 200, returned LOCAL_E2E_SECRET_CHAT_CONTENT
GET /api/v1/internal-chatmessage/:id -> 200, returned LOCAL_E2E_SECRET_CHAT_CONTENT
DELETE /api/v1/chatmessage/:id -> 200, {"raw":[],"affected":1}
Patched local server:
GET /api/v1/chatmessage/:id -> 403
GET /api/v1/internal-chatmessage/:id -> 403
DELETE /api/v1/chatmessage/:id -> 403
GET /api/v1/chatmessage/:id with allowed key -> 200
The local server E2E used only dummy data and localhost requests.
Patch proposal
Add route-level permission checks:
GET /chatmessage/:id: checkAnyPermission('chatflows:view,agentflows:view')
GET /internal-chatmessage/:id: checkAnyPermission('chatflows:view,agentflows:view')
DELETE /chatmessage/:id: checkAnyPermission('chatflows:delete,agentflows:delete')
Credit request
If this is accepted as a valid vulnerability, please credit GGBoo as the reporter/researcher.
Title
Missing RBAC checks on Flowise chat message routes allow low-privileged API keys to read and delete chat history
Description
Flowise
flowise@3.1.2appears to have missing route-level RBAC checks on chat message read/delete routes.The global
/api/v1middleware validates API keys and assignsreq.user.permissions = apiKey.permissions, but the affected chat message routes call their controllers directly withoutcheckAnyPermission(...).Affected files:
packages/server/src/routes/chat-messages/index.tspackages/server/src/routes/internal-chat-messages/index.tsAffected routes:
GET /api/v1/chatmessage/:idGET /api/v1/internal-chatmessage/:idDELETE /api/v1/chatmessage/:idConfirmed affected release:
flowise@3.1.24114b3b506e7bbee155141175a2ba48e426919ddImpact
A valid but low-privileged API key for a workspace can reach chat message read/delete handlers without having the expected flow permissions.
Potential impact:
Suggested CVSS v3.1:
Estimated severity: High, 8.3.
Affected versions
Confirmed:
flowise@3.1.2Broader affected range:
Reproduction steps
Observe insufficient-permission requests return 200 instead of 403.
Apply the route patch.
Run the same test again.
Observe insufficient-permission requests return 403, while requests with
chatflows:view,agentflows:view, oragentflows:deletecontinue to succeed.Safe PoC
The PoC is a Jest/supertest test with mocked controllers. It uses dummy data only and does not touch real users, credentials, or a database.
Pre-patch observed output:
Post-patch observed output:
I also reproduced the issue against a real local Flowise server with a dummy SQLite database:
The local server E2E used only dummy data and localhost requests.
Patch proposal
Add route-level permission checks:
GET /chatmessage/:id:checkAnyPermission('chatflows:view,agentflows:view')GET /internal-chatmessage/:id:checkAnyPermission('chatflows:view,agentflows:view')DELETE /chatmessage/:id:checkAnyPermission('chatflows:delete,agentflows:delete')Credit request
If this is accepted as a valid vulnerability, please credit GGBoo as the reporter/researcher.