Junglewise Threat Intelligence

CVE-2026-46480: FlowiseAI Flowise mass assignment in Evaluators endpoint

CVE-2026-46480 · Severity: high · CVSS 3.1 · Published 2026-06-08

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

FlowiseAI is an open-source tool for building LLM-based applications. A security flaw allows an authorized user in one workspace to move their data into a different workspace by manipulating internal ID fields. This could lead to unauthorized data access or the ability to interfere with the operations of other teams or customers using the same installation.

Technical details

A mass-assignment vulnerability (CWE-915) exists in the Evaluator component of FlowiseAI due to the use of 'Object.assign()' on the request body without an explicit field allowlist. An authenticated attacker can include a 'workspaceId' in a PUT or POST request to the '/api/v1/evaluators' endpoint to reassign an evaluator entity to a different workspace. This bypasses workspace isolation, allowing the attacker to move resources into workspaces they do not own or take over evaluators in other contexts. The vulnerability is rooted in 'packages/server/src/Interface.Evaluation.ts' and has been patched in version 3.1.2 by implementing a strict field allowlist.

Affected products

  • FlowiseAI Flowise <= 3.1.1

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory
  • 2026-05-14: patched

References

Related threats