Flowise User Interface Vulnerability in Drag & Drop Large Language Model Tool
CVE-2026-70475

7.1HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70475?

A security flaw in Flowise, a drag & drop interface used to build customized large language model workflows, allows any authenticated user to access and modify execution state, data, and metadata via the PUT /api/v1/executions/:id endpoint. This endpoint, lacking necessary permission checks, can lead to unauthorized privilege escalation and manipulation of workflow outcomes. The issue has been resolved in version 3.1.3, thus emphasizing the importance of updating to this version to safeguard against potential exploitation.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.