HIGH
Flowise before 3.1.3 Credential Exposure via API
Published Aug 13, 2026
7.1
HIGHCVSS 4.0
EPSS 0.41%
Description
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint.
Affected products
-
- Version 0StatusaffectedConstraints<3.1.3
- Version 3.1.3StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
flowise
npm
Introduced 0 Fixed 3.1.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | flowise | 0 | 3.1.3 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57808 Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-rwrp-9823-p2xq exploitvendor-advisoryMitigationVendor Advisory
- https://www.vulncheck.com/advisories/flowise-before-credential-exposure-via-api third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57808 | Advisory | |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-rwrp-9823-p2xq | exploitvendor-advisoryMitigationVendor Advisory | |
| https://www.vulncheck.com/advisories/flowise-before-credential-exposure-via-api | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 13, 2026
Updated Aug 13, 2026
Reserved Aug 13, 2026
Link CVE-2026-73604
CISA Vulnrichment
Updated Aug 13, 2026
ENISA EUVD
EUVD-2026-57808 Assigner VulnCheck
Published Aug 13, 2026
Updated Aug 13, 2026
Exploited since n/a
Link EUVD-2026-57808