A vulnerability categorized as critical has been discovered in FlowiseAI Flowise up to 3.1.2. Impacted is an unknown function of the component openai-assistants-vector-store. Executing a manipulation of the argument credential can lead to permission issues.
This vulnerability appears as CVE-2026-70472. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.