CVE-2026-73604

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 12:17

Updated : 2026-09-04 19:39


NVD link : CVE-2026-73604

Mitre link : CVE-2026-73604

CVE.ORG link : CVE-2026-73604


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor