Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Vendors & Products |
Flowiseai
Flowiseai flowise |
Sat, 07 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13. | |
| Title | Flowise: Mass Assignment in `/api/v1/leads` Endpoint | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-07T05:08:55.583Z
Updated: 2026-03-09T20:44:24.747Z
Reserved: 2026-03-05T21:06:44.605Z
Link: CVE-2026-30822
Updated: 2026-03-09T20:35:40.470Z
Status : Awaiting Analysis
Published: 2026-03-07T05:16:27.483
Modified: 2026-03-09T13:35:34.633
Link: CVE-2026-30822
No data.
ReportizFlow