CVE-2026-46443

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response. The code properly omits encryptedData when no filter is used but fails to do so when a filter is used. This issue has been patched in version 3.1.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Flowise es una interfaz de usuario de arrastrar y soltar para construir un flujo de modelo de lenguaje grande personalizado. Antes de la versión 3.1.2, cuando las credenciales se obtienen con un parámetro de filtro credentialName, el campo encryptedData no se elimina de la respuesta. El código omite correctamente encryptedData cuando no se usa ningún filtro, pero no lo hace cuando se usa un filtro. Este problema ha sido parcheado en la versión 3.1.2.

11 Jun 2026, 04:08

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Flowiseai flowise
Flowiseai
References () https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2 - () https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2 - Product, Release Notes
References () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7g73-99r4-m4mj - () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7g73-99r4-m4mj - Exploit, Vendor Advisory
CPE cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

09 Jun 2026, 17:17

Type Values Removed Values Added
References () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7g73-99r4-m4mj - () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7g73-99r4-m4mj -

08 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 16:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-46443

Mitre link : CVE-2026-46443

CVE.ORG link : CVE-2026-46443


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor