Horizon Alert
Summary of the vulnerability and why it matters
This advisory details an authentication bypass vulnerability in Flowise, specifically affecting systems using Single Sign-On (SSO) with an "INVITED" user status. An attacker could potentially hijack an invitation by using an invited user's email address with a configured SSO provider, gaining unauthorized access to the invited user's account and organizational membership.
- Bypass allows unauthorized account access.
- It impacts how invited users gain access.
- Confirm relevance and exposure of invited accounts.
Attack Path
How an attacker could exploit the issue
An attacker can bypass authentication by exploiting a vulnerability in the single sign-on (SSO) login process of Flowise. If an attacker can authenticate to a configured SSO provider using an email address that matches a user who has been invited but has not yet accepted, they can hijack that invitation. This allows them to gain the invited user's access to the organization without possessing the original invitation token.
- Attacker needs SSO access and an invited user's email.
- Attacker triggers by completing SSO with invited user's email.
- Risk of unauthorized access and control of accounts.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to gain unauthorized access to an organization's resources. If an attacker can authenticate with any configured SSO provider using an email address that matches a pending invitation, they could take over that invitation and gain the invited user's access. This is possible for as long as the invitation remains valid, typically 24 hours.
- Invited user accounts and organization access.
- Authenticating with a pending invitee's email.
- Unauthorized active account access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical authentication bypass vulnerability in Flowise impacts organizations using enterprise or platform mode with SSO enabled. Responsibility likely falls to platform or application owners to identify all instances, confirm business criticality and network reachability, and then coordinate with security and vendor management teams for remediation.
- Owner: Platform or application owners.
- Verify: All Flowise instances and SSO configurations.
- Action: Plan remediation, coordinate with vendor.