Junglewise Threat Intelligence

CVE-2026-56276: Flowise mass assignment in user profile update endpoint

CVE-2026-56276 · Severity: medium · CVSS 4 · Published 2026-06-20

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise is a visual AI agent builder platform. A vulnerability in its user profile update API allows attackers who have obtained a user's session to permanently hijack that account by directly replacing the password hash without providing the old password. This defeats all normal password change protections, allowing attackers to lock legitimate users out and maintain permanent unauthorized access even if the original session token expires.

Technical details

The vulnerability is a mass assignment flaw (CWE-915) in the PUT /api/v1/user endpoint. The controller validates that the authenticated user's ID matches the request parameter (preventing cross-user IDOR), but then passes the entire request body unfiltered to the service layer. UserService.updateUser uses ORM merge without a field allowlist, allowing any User entity field including "credential" (password hash) to be overwritten. The vulnerable code bypasses the secure password change workflow that normally requires oldPassword, newPassword, and confirmPassword fields with validation. An attacker with an authenticated session can send a crafted PUT request with a pre-computed bcrypt hash in the "credential" field, directly replacing the stored password hash. Attack vector is network with low privilege requirements (authenticated user). Patch available in version 3.1.2; all versions ≤ 3.1.1 are affected.

Affected products

  • FlowiseAI Flowise <=3.1.1

Timeline

  • 2026-05-20: disclosed: GHSA-59fh-9f3p-7m39 published on GitHub Security Advisories
  • 2026-05-20: patched: Patch available in version 3.1.2

References

Related threats