CVE-2026-91937
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-943
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- FlowiseAI Flowise
- FlowiseAI Flowise
Weakness type
Related vulnerabilities
- CVE-2022-36084 — cruddl vulnerable to AQL injection through flexSearch
- CVE-2024-4872 — A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an
- CVE-2020-36195 — SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On
- CVE-2026-32248 — Parse Server: Account takeover via operator injection in authentication data identifier
- CVE-2026-30941 — Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
- CVE-2026-25514 — FacturaScripts has SQL Injection vulnerability in Autocomplete Actions
- CVE-2025-24787 — Parameter injection in DB connection URIs leading to local file inclusion in WhoDB
- CVE-2026-54350 — Budibase: Anonymous NoSQL operator injection via published-app query templates