Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations. | |
| Title | ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via /workflow/search | |
| First Time appeared |
Pandarobot
Pandarobot ruoyi Ai |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:pandarobot:ruoyi_ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pandarobot
Pandarobot ruoyi Ai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T15:04:58.390Z
Reserved: 2026-10-09T13:44:40.884Z
Link: CVE-2026-108111
No data.
No data.
No data.
OpenCVE Enrichment
No data.