PT-2026-71432 · Flowise · Flowise

CVE-2026-73604

·

Published

2026-08-04

·

Updated

2026-08-13

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.3
Description An incomplete credential redaction issue exists where the 'GET /api/v1/credentials/:id' endpoint returns decrypted secrets in plaintext. Authenticated users possessing the credentials:view permission can retrieve sensitive information, such as API keys, cloud service account JSON containing private keys, and database connection URLs with embedded passwords.
Recommendations Update to version 3.1.3 or later. Restrict the credentials:view permission to only trusted administrators to minimize the risk of unauthorized data retrieval.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73604
GHSA-RWRP-9823-P2XQ

Affected Products

Flowise