Executive brief
FlowiseAI is susceptible to a mass-assignment vulnerability in its CustomTemplate service, allowing authenticated users to transfer templates between workspaces.
Affected products
- FlowiseAI FlowiseAI
- npm flowise
Junglewise Threat Intelligence
Severity: high · CVSS 7.7 · Published 2026-05-14
Technologies: FlowiseAI, flowise (npm). Vendors: FlowiseAI, npm.
FlowiseAI is susceptible to a mass-assignment vulnerability in its CustomTemplate service, allowing authenticated users to transfer templates between workspaces.