ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ageerle
Ageerle ruoyi-ai |
|
| Vendors & Products |
Ageerle
Ageerle ruoyi-ai |
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations. | |
| Title | ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via /workflow/search | |
| First Time appeared |
Pandarobot
Pandarobot ruoyi Ai |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:pandarobot:ruoyi_ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pandarobot
Pandarobot ruoyi Ai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T17:24:06.343Z
Reserved: 2026-10-09T13:44:40.884Z
Link: CVE-2026-108111
No data.
Status : Deferred
Published: 2026-10-09T16:17:26.607
Modified: 2026-10-09T16:45:01.980
Link: CVE-2026-108111
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:15:09Z
Weaknesses