Executive brief
Flowise is a visual AI agent building platform used to create and manage AI workflows. The account registration endpoint has a flaw that allows attackers to bypass security controls and inject themselves into existing organizations during account creation without authorization. An attacker can exploit this to gain unauthorized access to another organization's data and resources, escalate privileges, and compromise the integrity of the multi-tenant system.
Technical details
The vulnerability is a mass assignment / JSON injection flaw in the POST /api/v1/account/register endpoint. The backend fails to enforce strict allowlist or DTO-based validation and instead blindly maps all client-supplied JSON fields to internal domain models. An unauthenticated attacker can inject server-managed fields (createdBy, updatedBy, createdDate, updatedDate) and nested objects (organization, organizationUser, workspace, workspaceUser) with arbitrary values. These fields are persisted as-is without server-side generation or validation. By specifying an existing organizationId and owner roleId during registration, an attacker can create a new account associated with an organization they do not belong to, resulting in unauthorized cross-tenant access and privilege escalation. The issue affects Flowise versions ≤ 3.0.13 and was fixed in version 3.1.0.
Affected products
- FlowiseAI Flowise ≤ 3.0.13
Timeline
- 2026-04-16: disclosed: GHSA published
- 2026-04-16: patched: Fix released in version 3.1.0
- 2026-04-23: advisory: NVD published CVE-2026-41267