Flowise: Mass Assignment in `/api/v1/leads` Endpoint
26Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 13%
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected products
FlowiseAI · Flowise