Executive brief
FlowiseAI is an open-source tool used to build and manage AI workflows. A security flaw allows an authorized user in one workspace to move or 'take over' workflow templates belonging to other workspaces. This could lead to unauthorized access to proprietary AI templates or disruption of services for other users on the same platform.
Technical details
A mass-assignment vulnerability exists in the CustomTemplate service due to the use of Object.assign() on the request body without an explicit field allowlist. An authenticated attacker can include a 'workspaceId' in a create or update request to reassign a template to a different workspace. This breaks workspace isolation and allows for cross-workspace data takeover or Insecure Direct Object Reference (IDOR) attacks. The vulnerability is located in 'packages/server/src/services/marketplaces/index.ts'. A fix is available in version 3.1.2 which implements a strict allowlist for object properties.
Affected products
- FlowiseAI FlowiseAI <= 3.1.1
Timeline
- 2026-05-14: disclosed
- 2026-05-14: patched: Fixed in version 3.1.2
- 2026-05-14: advisory