CVE-2026-30822 Details
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.
A mass assignment vulnerability has been identified in Flowise, a user interface for building customized large language model flows. This vulnerability, present in versions through 3.0.12, allows unauthenticated users to inject arbitrary values into internal database fields when creating leads. The issue arises because the application whitelists the '/api/v1/leads' endpoint, enabling unauthorized access. Exploitation involves manipulating fields that should be auto-generated by the server, such as 'id' and 'createdDate', as well as 'chatId'. The vulnerability has been patched in version 3.0.13.
Users can update to Flowise version 3.0.13, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.13 | [email protected] | ProductRelease Notes |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-mq4r-h2gh-qv7x | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| flowiseai flowise | < 3.0.13 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 7, 2026 | New CVE Received | [email protected] |