Improperly Controlled Modification of Dynamically-Determined Object Attributes in Flowise - CVE-2026-42861
Published: May 18, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote user to reassign variable resources to arbitrary workspaces and modify metadata fields.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the variable update endpoint when processing JSON update requests. A remote user can send a crafted PUT request with attacker-controlled internal properties to reassign variable resources to arbitrary workspaces and modify metadata fields.
This may break tenant isolation in multi-workspace environments.