Improperly Controlled Modification of Dynamically-Determined Object Attributes in Flowise - CVE-2026-42861

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Flowise - CVE-2026-42861

Published: May 18, 2026


Vulnerability identifier: #VU131704
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-42861
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: FlowiseAI
Affected software:
Flowise

Detailed vulnerability description

The vulnerability allows a remote user to reassign variable resources to arbitrary workspaces and modify metadata fields.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the variable update endpoint when processing JSON update requests. A remote user can send a crafted PUT request with attacker-controlled internal properties to reassign variable resources to arbitrary workspaces and modify metadata fields.

This may break tenant isolation in multi-workspace environments.


How to mitigate CVE-2026-42861

Install security update from vendor's website.

Sources