Mass Assignment Vulnerability in Flowise by FlowiseAI
CVE-2026-46441
7.6HIGH
What is CVE-2026-46441?
A mass assignment vulnerability has been discovered in Flowise's assistant update endpoint, allowing authenticated users to change server-controlled properties such as workspaceId, createdDate, and updatedDate. This vulnerability stems from insufficient server-side validation and authorization checks, which enables an attacker to manipulate the workspaceId and incorrectly reassign assistants to arbitrary workspaces. This compromises tenant isolation within multi-workspace setups. The issue was resolved in version 3.1.2.
Affected Version(s)
Flowise < 3.1.2
