Cleartext storage of sensitive information in Flowise - #VU146556
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to cleartext storage of sensitive information in the exportData() function and Variable entity export path when exporting workspace data. A remote user can export workspace data or obtain an export file to disclose sensitive information.
The issue exposes Flowise Variable values such as API keys, database connection strings, and service tokens in plaintext.