What happened
Verified via NVD REST API (published 2026-10-09, VulnCheck): two missing-authorization (CWE-862) flaws in ruoyi-ai 3.0.0-3.1.0. GET /workflow/search exposes other users' private workflows (UUIDs + full node/edge config) because it lacks owner/is_public filtering; POST /workflow/del/{uuid} allows deleting owners' workflows because softDelete() skips the ownership check. CISA SSVC notes a PoC for the search disclosure.
Why it matters
Workflow definitions in an AI-agent platform are high-value IP and configuration secrets (prompts, model endpoints, tool wiring); the pair gives any authenticated user full read/delete control over other tenants' AI workflows — cross-tenant integrity and confidentiality loss in the agent platform.
Attack vector
Authenticated non-admin user queries /workflow/search to enumerate private workflow UUIDs (CVE-2026-108111), then POSTs /workflow/del/{uuid} for other users' flows because softDelete() bypasses PrivilegeUtil.checkAndGetByUuid() (CVE-2026-108112).
Affected systems
ruoyi-ai 3.0.0 - 3.1.0 (opensource AI workflow platform)
Mitigation
No patched release confirmed in the repo; apply authorization checks on /workflow/search and /workflow/del. References: https://www.vulncheck.com/advisories/ruoyi-ai-3.0.0-through-3.1.0-missing-authorization-via-workflow-delete-endpoint and ...-via-workflow-search