Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint. | |
| Title | Flowise before 3.1.3 Credential Exposure via API | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:52:32.624Z
Reserved: 2026-08-13T11:15:12.096Z
Link: CVE-2026-73604
No data.
Status : Received
Published: 2026-08-13T12:17:24.750
Modified: 2026-08-13T15:20:18.923
Link: CVE-2026-73604
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:00:04Z