Improperly Controlled Modification of Dynamically-Determined Object Attributes in Flowise - CVE-2026-41277
Published: April 20, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote user to modify or reassign DocumentStore objects across workspaces.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the DocumentStore create endpoint when handling crafted POST requests with client-supplied primary keys and internal state fields. A remote user can send a specially crafted request to modify or reassign DocumentStore objects across workspaces.
Exploitation requires obtaining or enumerating a valid DocumentStore UUID and is relevant in multi-workspace or multi-tenant deployments.