Mass Assignment Vulnerability in Flowise Drag & Drop User Interface
CVE-2026-46477
7.7HIGH
What is CVE-2026-46477?
Flowise, a user-friendly drag & drop interface designed for customizing large language model flows, experienced a significant vulnerability before version 3.1.2. This security issue allowed unauthorized users to exploit mass assignment capabilities in dataset creation and updates, which potentially led to cross-workspace dataset takeover. Users are strongly encouraged to upgrade to version 3.1.2 or later to mitigate this risk and protect their data against unauthorized access.
Affected Version(s)
Flowise < 3.1.2
