


Perceptive Security
SOC/SIEM Consultancy

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerabil…
Published:
22 april 2026 om 22:00:00
Alert date:
23 april 2026 om 21:01:44
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization, Emerging Technologies
CVE-2026-41267 affects Flowise, a drag-and-drop interface for building large language model flows. Prior to version 3.1.0, an improper mass assignment (JSON injection) vulnerability exists in the account registration endpoint of Flowise Cloud. This allows unauthenticated attackers to inject server-managed fields and nested objects during account creation. Attackers can manipulate ownership metadata, timestamps, organization associations, and role mappings. The vulnerability breaks trust boundaries in multi-tenant environments. The issue has been fixed in version 3.1.0.
Technical details
Mitigation steps:
Affected products:
Flowise
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41267
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-48m6-ch88-55mj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
