CVE-2026-41267 | Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
Exp
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objects during account creation. This enables client-controlled manipulation of ownership metadata, timestamps, organization association, and role mappings, breaking trust boundaries in a multi-tenant environment. This vulnerability is fixed in 3.1.0.
Conclusion & alert: CVE-2026-41267 is rated High Exploit Risk (73.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.83%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2026-41267
Exploit prediction scoring system (EPSS) score for CVE-2026-41267
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-48m6-ch88-55mj · Severity: high · Ecosystem: npm — Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
Affected software / configurations for CVE-2026-41267