ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability that allows authenticated users to delete other users' workflows via POST /workflow/del/{uuid}. Attackers can obtain workflow UUIDs from GET /workflow/search and supply them because softDelete() skips the PrivilegeUtil.checkAndGetByUuid() ownership check, removing owners' workflows.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ageerle
Ageerle ruoyi-ai |
|
| Vendors & Products |
Ageerle
Ageerle ruoyi-ai |
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability that allows authenticated users to delete other users' workflows via POST /workflow/del/{uuid}. Attackers can obtain workflow UUIDs from GET /workflow/search and supply them because softDelete() skips the PrivilegeUtil.checkAndGetByUuid() ownership check, removing owners' workflows. | |
| Title | ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via Workflow Delete Endpoint | |
| First Time appeared |
Pandarobot
Pandarobot ruoyi Ai |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:pandarobot:ruoyi_ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pandarobot
Pandarobot ruoyi Ai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T15:04:59.016Z
Reserved: 2026-10-09T13:44:40.884Z
Link: CVE-2026-108112
No data.
Status : Deferred
Published: 2026-10-09T16:17:26.767
Modified: 2026-10-09T16:45:01.980
Link: CVE-2026-108112
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:45:09Z
Weaknesses