Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.
Metrics
Affected Vendors & Products
References
History
Sat, 07 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13. | |
| Title | Flowise: Mass Assignment in `/api/v1/leads` Endpoint | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-07T05:08:55.583Z
Reserved: 2026-03-05T21:06:44.605Z
Link: CVE-2026-30822
No data.
Status : Received
Published: 2026-03-07T05:16:27.483
Modified: 2026-03-07T05:16:27.483
Link: CVE-2026-30822
No data.
OpenCVE Enrichment
No data.