Junglewise Threat Intelligence

FlowiseAI mass assignment in Evaluator component

Severity: high · CVSS 7.7 · Published 2026-05-14

Technologies: flowise (npm). Vendors: npm.

Executive brief

FlowiseAI Evaluator create and update operations are vulnerable to mass-assignment, allowing authenticated users to move evaluators across workspace boundaries.

Affected products

  • npm flowise

Related threats