Mass Assignment Vulnerability in Flowise by FlowiseAI
CVE-2026-42861
7.6HIGH
What is CVE-2026-42861?
Flowise, a drag & drop user interface developed by FlowiseAI, is vulnerable to a mass assignment issue in its variable update endpoint prior to version 3.1.2. Authenticated users can exploit this vulnerability to modify critical server-controlled properties, including workspaceId, createdDate, and updatedDate. The lack of adequate server-side validations and authorization checks exposes the risk of unauthorized variable reassignment to arbitrary workspaces, which can compromise tenant isolation in environments that support multiple workspaces. This security flaw has been addressed in version 3.1.2.
Affected Version(s)
Flowise < 3.1.2
