Cleartext storage of sensitive information in Flowise - #VU146556

 

Cleartext storage of sensitive information in Flowise - #VU146556

Published: September 1, 2026


Vulnerability identifier: #VU146556
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to cleartext storage of sensitive information in the exportData() function and Variable entity export path when exporting workspace data. A remote user can export workspace data or obtain an export file to disclose sensitive information.

The issue exposes Flowise Variable values such as API keys, database connection strings, and service tokens in plaintext.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins