Executive brief
FlowiseAI contains a mass assignment vulnerability in its assistant update endpoint that allows authenticated users to reassign assistants to arbitrary workspaces, breaking tenant isolation.
Affected products
- npm flowise
Junglewise Threat Intelligence
Severity: high · CVSS 7.6 · Published 2026-05-14
Technologies: flowise (npm). Vendors: npm.
FlowiseAI contains a mass assignment vulnerability in its assistant update endpoint that allows authenticated users to reassign assistants to arbitrary workspaces, breaking tenant isolation.