PT-2026-34732 · Flowise · Flowise

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41267

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description An improper mass assignment (JSON injection) issue exists in the account registration endpoint of Flowise Cloud. This allows unauthenticated attackers to inject server-managed fields and nested objects during account creation, enabling client-controlled manipulation of ownership metadata, timestamps, organization association, and role mappings, which breaks trust boundaries in a multi-tenant environment.
Recommendations Update to version 3.1.0.

Exploit

Fix

IDOR

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41267
GHSA-48M6-CH88-55MJ

Affected Products

Flowise