Mass Assignment Vulnerability in Flowise AI by Flowise
CVE-2026-42862

7.6HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-42862?

Flowise AI, a drag-and-drop user interface for building customized large language model flows, is vulnerable to a mass assignment issue in its tool update endpoint. This issue allows authenticated users to alter server-controlled properties such as workspaceId, createdDate, and updatedDate. The lack of adequate server-side validation and authorization checks means that an attacker can exploit this vulnerability to manipulate the workspaceId field, thereby reassigning tools to unauthorized workspaces. This breach compromises tenant isolation in multi-workspace environments, potentially leading to significant data integrity concerns. The vulnerability has been addressed in version 3.1.2.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.