Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.
References
| Link | Resource |
|---|---|
| https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.13 | Product Release Notes |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-mq4r-h2gh-qv7x | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-07 05:16
Updated : 2026-03-11 13:40
NVD link : CVE-2026-30822
Mitre link : CVE-2026-30822
CVE.ORG link : CVE-2026-30822
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
