Junglewise Threat Intelligence

FlowiseAI mass assignment in Evaluation service

Severity: high · CVSS 7.7 · Published 2026-05-14

Technologies: flowise (npm). Vendors: npm.

Executive brief

FlowiseAI is an open-source tool used to build customized AI workflows. A vulnerability in the evaluation component allows an authorized user to move data between different organizational workspaces. This could lead to unauthorized access to sensitive AI prompts, model outputs, and scoring data by moving them into a workspace controlled by the attacker.

Affected products

  • npm flowise

Related threats