Description
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via NoSQL injection
Action: Upgrade
AI Analysis

Impact

Flowise before version 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before it is used in MongoDB queries within the MongoDBMemory node. This omission allows an unauthenticated attacker to inject MongoDB operator objects through the prediction API, causing the application to execute arbitrary query operators that can return chat history records from the shared collection. The result is an untrusted entity obtaining confidential message data from other users, exposing sensitive conversation content.

Affected Systems

The vulnerability affects FlowiseAI's Flowise platform in all releases prior to 3.1.4. Notably any deployment of Flowise that has not applied the 3.1.4 patch is susceptible. Users should verify that their version is 3.1.4 or later to eliminate the risk.

Risk and Exploitability

The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score of 0.00277 indicates a very low but nonzero probability of exploitation, and it is not included in CISA's KEV catalog. The vulnerability can be exploited by sending crafted requests to the public prediction API with no authentication, making it readily accessible to remote attackers. The exploitation path relies on the application’s direct use of unsanitized user input in a database query, which is typical of NoSQL injection vectors.

Generated by OpenCVE AI on September 20, 2026 at 16:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 or later to apply the vendor’s fix.
  • If an immediate upgrade is not possible, enforce authentication on the prediction API and validate or sanitize the overrideConfig.sessionId value to prevent injection of MongoDB operator objects.
  • Monitor API logs for anomalous requests containing MongoDB operators and audit the MongoDB collection for unauthorized data reads.

Generated by OpenCVE AI on September 20, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
Title Flowise before 3.1.4 NoSQL Injection via sessionId
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-943
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T17:02:01.493Z

Reserved: 2026-09-15T11:06:02.263Z

Link: CVE-2026-91937

cve-icon Vulnrichment

Updated: 2026-09-15T17:01:53.497Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:45.170

Modified: 2026-09-23T17:17:47.107

Link: CVE-2026-91937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic