Количество 2
Количество 2
CVE-2026-41266
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID can retrieve credentials stored in password type fields and HTTP headers, leading to credential theft and more. This vulnerability is fixed in 3.1.0.
GHSA-4jpm-cgx2-8h37
Flowise: Sensitive Data Leak in public-chatbotConfig
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41266 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID can retrieve credentials stored in password type fields and HTTP headers, leading to credential theft and more. This vulnerability is fixed in 3.1.0. | CVSS3: 7.5 | 4% Низкий | 5 месяцев назад | |
GHSA-4jpm-cgx2-8h37 Flowise: Sensitive Data Leak in public-chatbotConfig | CVSS3: 7.5 | 4% Низкий | 5 месяцев назад |
Уязвимостей на страницу