#VU125526 Information disclosure in Flowise
Published: April 9, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in the POST /api/v1/account/forgot-password endpoint when handling forgot-password requests with a valid email address. A remote attacker can send a specially crafted request containing a known email address to disclose sensitive information.
The response may include user id, name, email, status, timestamps, and internal reference fields.