CVE-2026-42861 HIGH

CVE-2026-42861: Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment

Vendor Flowiseai
Product Flowise
Weakness CWE-284
Published June 8, 2026
Last update June 9, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a variable resource. Due to missing server-side validation and authorization checks, an attacker can manipulate the workspaceId field and reassign variables to arbitrary workspaces. This behavior may break tenant isolation in multi-workspace environments. This issue has been patched in version 3.1.2.

Key dates

02Disclosure timeline

June 8, 2026 CVE published
June 9, 2026 Record updated