CVE-2026-41267: Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objects during account creation. This enables client-controlled manipulation of ownership metadata, timestamps, organization association, and role mappings, breaking trust boundaries in a multi-tenant environment. This vulnerability is fixed in 3.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41267?
CVE-2026-41267 has been rated as a high-severity vulnerability due to its potential to allow unauthorized association of organizations during account registration.
How do I fix CVE-2026-41267?
To fix CVE-2026-41267, update to Flowise version 3.1.0 or later, where this vulnerability has been addressed.
Who is affected by CVE-2026-41267?
CVE-2026-41267 affects users of Flowise prior to version 3.1.0, particularly those utilizing the account registration feature.
What type of vulnerability is CVE-2026-41267?
CVE-2026-41267 is classified as an improper mass assignment vulnerability, which allows for JSON injection during account registration.
What impact does CVE-2026-41267 have on users?
The impact of CVE-2026-41267 allows unauthorized users to associate themselves with other organizations, potentially leading to unauthorized access.