PT-2026-54029 · Flowise · Flowise
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions 3.0.13 and earlier
Description
The software uses a weak hardcoded default secret ('flowise') for the express-session middleware when the
EXPRESS SESSION SECRET environment variable is not set. Since this secret is publicly visible in the source code, an attacker can forge valid signed session cookies to impersonate any user and bypass authentication.Recommendations
Update to version 3.1.0 or later.
Set the
EXPRESS SESSION SECRET environment variable to a strong, unique value.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise