CVE-2026-41277: Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint behaves as an implicit UPSERT operation. This enables overwriting existing DocumentStore objects. In multi-workspace or multi-tenant deployments, this can lead to cross-workspace object takeover and broken object-level authorization (IDOR), allowing an attacker to reassign or modify DocumentStore objects belonging to other workspaces. This vulnerability is fixed in 3.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41277?
CVE-2026-41277 has a high severity due to the potential for unauthorized access and object takeover across workspaces.
How do I fix CVE-2026-41277?
To fix CVE-2026-41277, it is recommended to upgrade Flowise to version 3.1.0 or later.
What type of vulnerability is CVE-2026-41277?
CVE-2026-41277 is classified as a Mass Assignment vulnerability leading to an Insecure Direct Object Reference (IDOR).
Who is affected by CVE-2026-41277?
CVE-2026-41277 affects users of Flowise versions prior to 3.1.0.
What are the potential impacts of CVE-2026-41277?
The potential impacts of CVE-2026-41277 include unauthorized access to sensitive data and manipulation of object states across different workspaces.