CVE-2026-42861

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a variable resource. Due to missing server-side validation and authorization checks, an attacker can manipulate the workspaceId field and reassign variables to arbitrary workspaces. This behavior may break tenant isolation in multi-workspace environments. This issue has been patched in version 3.1.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Flowise es una interfaz de usuario de arrastrar y soltar para construir un flujo de modelo de lenguaje grande personalizado. Antes de la versión 3.1.2, existe una vulnerabilidad de asignación masiva en el endpoint de actualización de variables de FlowiseAI. El endpoint permite a los usuarios autenticados modificar propiedades controladas por el servidor como workspaceId, createdDate y updatedDate al actualizar un recurso de variable. Debido a la falta de validación del lado del servidor y de comprobaciones de autorización, un atacante puede manipular el campo workspaceId y reasignar variables a espacios de trabajo arbitrarios. Este comportamiento puede romper el aislamiento de inquilinos en entornos multi-espacio de trabajo. Este problema ha sido parcheado en la versión 3.1.2.

11 Jun 2026, 03:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
CPE cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
References () https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2 - () https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2 - Product, Release Notes
References () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6fw7-3q8r-m5vj - () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6fw7-3q8r-m5vj - Exploit, Vendor Advisory
First Time Flowiseai flowise
Flowiseai

08 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 16:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-42861

Mitre link : CVE-2026-42861

CVE.ORG link : CVE-2026-42861


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes