PT-2026-41208 · Flowiseai+2 · Flowise

CVE-2026-46443

·

Published

2026-05-14

·

Updated

2026-06-11

CVSS v4.0

7.0

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.2
Description An issue exists where the encryptedData field is not stripped from the response when credentials are fetched using a credentialName filter parameter. While the system correctly omits this field when no filter is applied, it fails to do so when a filter is used. This allows authenticated users to extract encrypted credential data, such as API keys, passwords, and tokens for services like OpenAI and AWS. If an attacker also gains access to the encryption key file located at ~/.flowise/encryption.key, they can achieve full credential theft.
Recommendations Update to version 3.1.2.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46443
GHSA-7G73-99R4-M4MJ

Affected Products

Flowise