NoSQL Injection Vulnerability in Flowise by FlowiseAI
CVE-2026-91937
8.7HIGH
What is CVE-2026-91937?
Flowise versions prior to 3.1.4 are vulnerable to a NoSQL injection attack due to improper sanitization of the overrideConfig.sessionId parameter. This flaw allows unauthenticated attackers to construct malicious MongoDB operator objects through the prediction API. By exploiting this vulnerability, attackers can gain unauthorized access to chat history records from a shared MongoDB collection, potentially exposing sensitive user information.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 3.1.4
