Junglewise Threat Intelligence

CVE-2026-46475: Flowise mass assignment in Assistant endpoints allows cross-workspace takeover

CVE-2026-46475 · Severity: high · CVSS 3.1 · Published 2026-06-08

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

FlowiseAI, a platform for building LLM applications, contains a vulnerability that allows an authenticated user to move AI assistants between different organizational workspaces. By manipulating internal identifiers during an update, an attacker can 'steal' an assistant from another workspace or move their own into a target workspace. This could lead to the exposure of sensitive AI configurations, system prompts, and connected tools to unauthorized users.

Technical details

A mass-assignment vulnerability exists in `packages/server/src/services/assistants/index.ts` due to the use of `Object.assign()` to copy request bodies directly into database entities. Because the application fails to use an allowlist for permitted fields, an attacker can include sensitive internal fields like `workspaceId` or `id` in a PUT or POST request. By supplying a target workspace's UUID, an authenticated attacker can reassign an Assistant entity to a different workspace, effectively bypassing logical isolation. This allows for cross-workspace data exfiltration of LLM instructions and tool configurations. The issue is fixed in version 3.1.2 by implementing an explicit field allowlist.

Affected products

  • FlowiseAI flowise <= 3.1.1

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: patched: Fixed in version 3.1.2
  • 2026-06-08: advisory: NVD publication date

References

Related threats