Description


ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations.

Related CPE's


Could not find any relations

Weaknesses



CWE-862

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-09T16:17:26.607Z

2 hours ago

Last modified

2026-10-09T18:17:06.857Z

15 minutes ago