Mass Assignment Vulnerability in Flowise by FlowiseAI
CVE-2026-42861

7.6HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-42861?

Flowise, a drag & drop user interface developed by FlowiseAI, is vulnerable to a mass assignment issue in its variable update endpoint prior to version 3.1.2. Authenticated users can exploit this vulnerability to modify critical server-controlled properties, including workspaceId, createdDate, and updatedDate. The lack of adequate server-side validations and authorization checks exposes the risk of unauthorized variable reassignment to arbitrary workspaces, which can compromise tenant isolation in environments that support multiple workspaces. This security flaw has been addressed in version 3.1.2.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.