Cross-Workspace Vulnerability in Flowise by FlowiseAI
CVE-2026-46479
7.7HIGH
What is CVE-2026-46479?
Flowise, a drag-and-drop interface designed to create custom flows for large language models, contains a vulnerability prior to version 3.1.2 that allows for cross-workspace evaluation takeover through improper handling of mass-assignment in evaluation creation and updates. This flaw can potentially lead to unauthorized access and manipulation of user evaluations, posing a significant security risk. Users are strongly encouraged to update to the patched version 3.1.2 to mitigate this vulnerability.
Affected Version(s)
Flowise < 3.1.2
