Information disclosure in Flowise - #VU125526

 

Information disclosure in Flowise - #VU125526

Published: April 9, 2026


Vulnerability identifier: #VU125526
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in the POST /api/v1/account/forgot-password endpoint when handling forgot-password requests with a valid email address. A remote attacker can send a specially crafted request containing a known email address to disclose sensitive information.

The response may include user id, name, email, status, timestamps, and internal reference fields.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.0.13

External References

Related Security Bulletins