Executive brief
FlowiseAI Evaluator create and update operations are vulnerable to mass-assignment, allowing authenticated users to move evaluators across workspace boundaries.
Affected products
- npm flowise
Junglewise Threat Intelligence
Severity: high · CVSS 7.7 · Published 2026-05-14
Technologies: flowise (npm). Vendors: npm.
FlowiseAI Evaluator create and update operations are vulnerable to mass-assignment, allowing authenticated users to move evaluators across workspace boundaries.