Cross-Workspace Evaluator Takeover in Flowise by FlowiseAI
CVE-2026-46480
7.7HIGH
What is CVE-2026-46480?
Flowise, a drag-and-drop user interface designed for customizing large language model flows, contains a vulnerability that allows for cross-workspace evaluator takeover. This flaw exists in the evaluator's mass-assignment functionality and poses a significant risk to user data integrity. The issue has been addressed and patched in version 3.1.2, urging all users to update promptly to mitigate potential security threats.
Affected Version(s)
Flowise < 3.1.2
