#VU125530 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Flowise - CVE-2026-30822
Published: April 9, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote attacker to modify internal lead entity fields and compromise data integrity.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the /api/v1/leads endpoint when handling lead creation requests. A remote attacker can send a specially crafted request body to modify internal lead entity fields and compromise data integrity.
The issue allows control of server-managed fields such as id, createdDate, and chatId.