PT-2026-41208 · Flowiseai+2 · Flowise
CVE-2026-46443
·
Published
2026-05-14
·
Updated
2026-06-11
CVSS v4.0
7.0
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.2
Description
An issue exists where the
encryptedData field is not stripped from the response when credentials are fetched using a credentialName filter parameter. While the system correctly omits this field when no filter is applied, it fails to do so when a filter is used. This allows authenticated users to extract encrypted credential data, such as API keys, passwords, and tokens for services like OpenAI and AWS. If an attacker also gains access to the encryption key file located at ~/.flowise/encryption.key, they can achieve full credential theft.Recommendations
Update to version 3.1.2.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise