Mass Assignment Vulnerability in Flowise AI by Flowise
CVE-2026-42862
7.6HIGH
What is CVE-2026-42862?
Flowise AI, a drag-and-drop user interface for building customized large language model flows, is vulnerable to a mass assignment issue in its tool update endpoint. This issue allows authenticated users to alter server-controlled properties such as workspaceId, createdDate, and updatedDate. The lack of adequate server-side validation and authorization checks means that an attacker can exploit this vulnerability to manipulate the workspaceId field, thereby reassigning tools to unauthorized workspaces. This breach compromises tenant isolation in multi-workspace environments, potentially leading to significant data integrity concerns. The vulnerability has been addressed in version 3.1.2.
Affected Version(s)
Flowise < 3.1.2
