Flowise User Interface Vulnerability in Drag & Drop Large Language Model Tool
CVE-2026-70475
7.1HIGH
What is CVE-2026-70475?
A security flaw in Flowise, a drag & drop interface used to build customized large language model workflows, allows any authenticated user to access and modify execution state, data, and metadata via the PUT /api/v1/executions/:id endpoint. This endpoint, lacking necessary permission checks, can lead to unauthorized privilege escalation and manipulation of workflow outcomes. The issue has been resolved in version 3.1.3, thus emphasizing the importance of updating to this version to safeguard against potential exploitation.
Affected Version(s)
Flowise < 3.1.2
