Why it matters
In shared multi-tenant AI workflow automation deployments, this breaks the tenant isolation boundary that enterprise customers rely on, allowing one customer's low-privilege flow author to read or tamper with another customer's AI automation logic and embedded credentials.
Attack vector
An unsanitized path segment in the Code piece sandbox allows an authenticated flow author to reach read-write cached flow and code files belonging to other tenants sharing the same worker, exposing embedded secrets/data and allowing modification of other tenants' workflow code.
Affected systems
Activepieces prior to 0.84.0
Mitigation
Upgrade to Activepieces 0.84.0 or later.