Impact
Flowise before version 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before it is used in MongoDB queries within the MongoDBMemory node. This omission allows an unauthenticated attacker to inject MongoDB operator objects through the prediction API, causing the application to execute arbitrary query operators that can return chat history records from the shared collection. The result is an untrusted entity obtaining confidential message data from other users, exposing sensitive conversation content.
Affected Systems
The vulnerability affects FlowiseAI's Flowise platform in all releases prior to 3.1.4. Notably any deployment of Flowise that has not applied the 3.1.4 patch is susceptible. Users should verify that their version is 3.1.4 or later to eliminate the risk.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score of 0.00277 indicates a very low but nonzero probability of exploitation, and it is not included in CISA's KEV catalog. The vulnerability can be exploited by sending crafted requests to the public prediction API with no authentication, making it readily accessible to remote attackers. The exploitation path relies on the application’s direct use of unsanitized user input in a database query, which is typical of NoSQL injection vectors.
OpenCVE Enrichment