Mass Assignment Vulnerability in Flowise AI's Chatflow Update Interface
CVE-2026-42863

7.6HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-42863?

A mass assignment vulnerability in Flowise allows authenticated users to manipulate internal attributes of chatflow objects through the chatflow update endpoint. This security flaw results from the absence of proper server-side validation and authorization checks, permitting users to alter server-controlled properties such as deployment status, visibility settings, and workspace assignments. This vulnerability can lead to unauthorized modification of resources across different workspaces. The issue was addressed and patched in version 3.1.2 of Flowise.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.