Information disclosure in Flowise - CVE-2026-41278
Published: April 20, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of sensitive information in the GET /api/v1/public-chatflows/:id and public-chatbotConfig endpoints when handling requests for public chatflows. A remote attacker can send a request to a public chatflow endpoint to disclose sensitive information.
Exposed data can include credential IDs, plaintext API keys, password-type fields, node configurations, and endpoint URLs.