Junglewise Threat Intelligence

FlowiseAI mass assignment in dataset service allows cross-workspace takeover

Severity: high · CVSS 7.7 · Published 2026-05-14

Technologies: flowise (npm). Vendors: npm.

Executive brief

FlowiseAI is vulnerable to a mass-assignment bug in its dataset management service, allowing authenticated users to transfer datasets between workspaces by manipulating the workspaceId field.

Affected products

  • npm flowise

Related threats