Cleartext transmission of sensitive information in Flowise - CVE-2026-41275
Published: April 20, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to a victim's account.
The vulnerability exists due to insecure transmission of password reset links in password reset functionality when sending password reset links over unsecured HTTP. A remote attacker can intercept a password reset link on an untrusted network to gain unauthorized access to a victim's account.
User interaction is required because the victim must use the reset link, and exploitation depends on a man-in-the-middle position on the same network.