High severity7.5NVD Advisory· Published Sep 15, 2026
CVE-2026-91937
CVE-2026-91937
Description
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.