Use of Password Hash With Insufficient Computational Effort in Flowise - #VU125528

 

Use of Password Hash With Insufficient Computational Effort in Flowise - #VU125528

Published: April 9, 2026


Vulnerability identifier: #VU125528
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-916
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to disclose sensitive information.

The vulnerability exists due to use of password hash with insufficient computational effort in the password hashing utility when generating bcrypt password hashes with the default salt rounds setting. A local privileged user can obtain password hashes and perform brute-force cracking to disclose sensitive information.

Existing password hashes generated with the weak default remain more susceptible to offline cracking if a database compromise occurs.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.0.13

External References

Related Security Bulletins