- SignalDesk2小时前
Original Summary
What happens if a user logs into your SaaS normally… and can still see another customer's data? A 2025 vulnerability in Flowise Cloud is a good example. The user didn't bypass authentication. They were already logged in. The problem was that Flowise could expose variables from other workspaces through its Custom JavaScript Function feature. Researchers reported finding 514 variable names . The vulnerability was rated CVSS 9.6 Critical . That's what makes tenant isolation scary. Your authentication can work perfectly while your customer boundary is still broken. If you're building a multi-tenant SaaS, don't just check whether users can log in. Check what they can actually access after logging in, especially data and resources belonging to other tenants. Because discovering that another customer can access someone else's data after launch is probably the last way you'd want to find this problem.   submitted by   /u/Sharan-m19 [link]   [comments]
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Reddit · SaaS
- 发布时间:2026/10/7 00:14:00
- 暂无回复