Junglewise Threat Intelligence

CVE-2026-42862: FlowiseAI Flowise mass assignment in tool update endpoint

CVE-2026-42862 · Severity: high · CVSS 4 · Published 2026-06-08

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

FlowiseAI, a platform for building LLM-based applications, contains a flaw that allows users to move resources between different organizational workspaces. An authenticated user can exploit this to reassign tools to workspaces they do not own, effectively breaking the security boundaries between different teams or customers. This could lead to unauthorized access to proprietary tools or disruption of operations in other workspaces.

Technical details

A mass assignment vulnerability exists in the FlowiseAI tool update endpoint (PUT /api/v1/tools/{toolId}). The server fails to restrict which properties can be modified by the client, directly merging the JSON request body into the database entity without proper Data Transfer Object (DTO) validation. An authenticated attacker can inject server-controlled fields such as 'workspaceId', 'createdDate', and 'updatedDate' into the request. By manipulating the 'workspaceId', an attacker can reassign a tool to a different workspace, bypassing authorization checks and breaking multi-tenant isolation. The vulnerability is patched in version 3.1.2.

Affected products

  • FlowiseAI flowise <= 3.1.1

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory
  • 2026-05-14: patched: Fixed in version 3.1.2

References

Related threats