CVE-2026-41277 | FlowiseAI Flowise up to 3.0.x DocumentStore Creation Endpoint repository.save access control (GHSA-3prp-9gf7-4rxx / EUVD-2026-25296)
A vulnerability was found in FlowiseAI Flowise up to 3.0.x. It has been rated as critical. This vulnerability affects the function repository.save of the component DocumentStore Creation Endpoint. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2026-41277. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.