Executive brief
FlowiseAI is a visual AI agent builder used to create and deploy automated workflows. An authenticated user can exploit a mass assignment vulnerability in the chatflow update API to modify server-controlled properties such as deployment status, visibility, and workspace ownership. This allows attackers to move workflows between workspaces, disable isolation boundaries in multi-tenant deployments, and expose private workflows to unauthorized users.
Technical details
A mass assignment vulnerability exists in the PUT /api/v1/chatflows/{chatflowId} endpoint where the server accepts and persists client-controlled modifications to server-controlled properties including deployed, isPublic, workspaceId, createdDate, updatedDate, category, and type. The root cause is missing input validation and improper use of data transfer objects (DTOs)—the server performs a direct merge of the request body into the database model without whitelisting allowed fields or verifying workspace authorization. An authenticated attacker can capture and modify a chatflow update request to inject additional properties, causing the server to persist unauthorized changes. No user interaction is required beyond the attacker's own authenticated session. The vulnerability enables cross-workspace resource theft, unauthorized visibility changes, and disruption of tenant isolation in multi-tenant environments. A patch was released in version 3.1.2.
Affected products
- FlowiseAI Flowise <= 3.1.1
Timeline
- 2026-05-14: disclosed
- 2026-05-14: patched: Fix released in version 3.1.2