CVE-2026-108111: Ageerle Ruoyi-Ai

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations.

Affected products

  • Ageerle Ruoyi-Ai: from 3.0.0, up to and including 3.1.0

Published 2026-10-09. Last modified 2026-10-09.