Junglewise Threat Intelligence

CVE-2026-46477: Flowise mass assignment in Dataset operations allows cross-workspace takeover

CVE-2026-46477 · Severity: high · CVSS 3.1 · Published 2026-06-08

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

FlowiseAI Flowise is an AI agent builder platform that organizes training datasets within separate workspaces for different teams. A flaw in how the application processes dataset updates allows any authenticated user to reassign a dataset from one workspace to another by simply modifying a workspaceId field in the request. This breaks the fundamental security boundary between workspaces, potentially exposing sensitive training data to unauthorized teams and enabling dataset theft across organizational boundaries.

Technical details

The vulnerability exists in the dataset controller/service (packages/server/src/services/dataset/index.ts) which uses Object.assign() to copy request body properties directly onto a Dataset entity without an explicit field allowlist. The create and update endpoints fail to prevent client-supplied workspaceId values from overwriting the persisted entity's workspaceId column, allowing authenticated users to reassign datasets across workspace boundaries. The attack requires only a valid session with edit permission on a source dataset and knowledge of a target workspace's UUID (which are trivially enumerable via the /api/v1/workspaces endpoint and cross-referenced in API responses). No second factor or additional authentication is required. The fix, implemented in PR #6051 and version 3.1.2, applies an explicit field-by-field allowlist pattern to prevent sensitive fields (workspaceId, id, createdDate, updatedDate) from being accepted in request bodies.

Affected products

  • FlowiseAI Flowise <= 3.1.1

Timeline

  • 2026-05-14: disclosed: GHSA-5h9v-837x-m97r published
  • 2026-04-14: patched: Flowise 3.1.2 released with fix (PR #6051)

References

Related threats