Skip to main content
Vulnerability Database/CVE-2026-91937

CVE-2026-91937: Flowise MongoDB SQLI Vulnerability

CVE-2026-91937 is a SQL injection vulnerability in Flowise versions before 3.1.4 affecting MongoDB queries. Attackers can exploit unsanitized parameters to access chat history from other users. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-91937 Overview

CVE-2026-91937 is a NoSQL injection vulnerability in Flowise versions before 3.1.4. The flaw resides in the MongoDBMemory node, where the application fails to sanitize the overrideConfig.sessionId parameter before passing it to MongoDB queries. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection. The issue is classified under CWE-943: Improper Neutralization of Special Elements in Data Query Logic. Because the prediction endpoint accepts crafted input without authentication, exploitation requires no prior access to the target instance.

Critical Impact

Unauthenticated attackers can extract cross-tenant chat history containing prompts, model responses, and any sensitive data users shared with LLM workflows built on Flowise.

Affected Products

  • Flowise versions prior to 3.1.4
  • Deployments using the MongoDBMemory node for conversation memory
  • Self-hosted and containerized Flowise instances exposing the prediction API

Discovery Timeline

  • 2026-09-15 - CVE-2026-91937 published to NVD
  • 2026-09-15 - Last updated in NVD database

Technical Details for CVE-2026-91937

Vulnerability Analysis

Flowise is a low-code platform for building LLM applications and agent workflows. The MongoDBMemory node stores conversation history in a shared MongoDB collection, keyed by a sessionId value. Client requests to the prediction API can include an overrideConfig object that supplies runtime parameters, including sessionId. The application passes the client-supplied sessionId directly into a MongoDB query filter without type validation or operator stripping.

MongoDB query filters interpret nested objects as query operators. When a request supplies a JSON object rather than a string, operators such as $ne, $gt, or $regex execute against the collection. This allows an attacker to bypass the intended equality match and retrieve documents belonging to any session in the shared collection.

Root Cause

The root cause is missing input validation on a user-controlled query parameter [CWE-943]. The sessionId field is expected to be a string uniquely identifying a conversation, but the code neither enforces the string type nor filters MongoDB operator syntax. Because chat memory for all users lives in a single collection distinguished only by sessionId, a permissive query filter exposes records across tenants.

Attack Vector

An unauthenticated attacker sends a POST request to the prediction API endpoint of a Flowise instance running a chatflow that uses MongoDBMemory. The request body contains an overrideConfig object where sessionId is set to a MongoDB operator expression such as {"$ne": null} or {"$regex": ".*"}. The MongoDB driver evaluates the operator, returning chat memory documents for other users. The attacker parses the response to harvest prompts, model outputs, and any embedded sensitive data. See the VulnCheck advisory and the Flowise GitHub Security Advisory GHSA-wpvf-4vfx-rgxm for advisory details.

Detection Methods for CVE-2026-91937

Indicators of Compromise

  • HTTP requests to /api/v1/prediction/* endpoints containing JSON objects instead of strings in the overrideConfig.sessionId field.
  • Request bodies containing MongoDB operator syntax such as $ne, $gt, $regex, $where, or $exists inside overrideConfig.
  • Unusual response sizes from prediction endpoints returning chat history data not tied to the requesting session.
  • MongoDB query logs showing filter documents on the memory collection with operator expressions on the sessionId field.

Detection Strategies

  • Inspect application and reverse-proxy logs for POST bodies where overrideConfig.sessionId is not a string primitive.
  • Enable MongoDB profiling on the Flowise memory collection and alert on queries where sessionId filters contain operator keys.
  • Deploy a web application firewall rule that blocks JSON payloads containing MongoDB operators within overrideConfig.

Monitoring Recommendations

  • Baseline the normal request volume and response size for /api/v1/prediction/* and alert on statistical anomalies.
  • Monitor for repeated unauthenticated requests originating from a single source targeting prediction endpoints.
  • Forward Flowise access logs and MongoDB slow-query logs to a centralized analytics platform for correlation.

How to Mitigate CVE-2026-91937

Immediate Actions Required

  • Upgrade Flowise to version 3.1.4 or later on all self-hosted and containerized deployments.
  • Restrict network exposure of the prediction API to authenticated clients or trusted networks using a reverse proxy.
  • Audit the shared MongoDB memory collection for evidence of cross-session queries and rotate any credentials or secrets that may have appeared in chat history.

Patch Information

The maintainers fixed the issue in Flowise 3.1.4. Refer to the Flowise GitHub Security Advisory GHSA-wpvf-4vfx-rgxm for release notes and commit references. Upgrade using the standard container image or npm package for the platform.

Workarounds

  • Place Flowise behind an authenticating reverse proxy that requires valid credentials for all /api/v1/prediction/* requests.
  • Enforce a WAF rule that rejects request bodies where overrideConfig.sessionId is not a JSON string.
  • Isolate chat memory per tenant by deploying separate MongoDB collections or databases rather than sharing a single collection.
  • Disable the MongoDBMemory node in chatflows and substitute an alternative memory provider until patching is complete.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.