CVE-2026-46440 PUBLISHED

Flowise: Basic Auth Credentials Exposed via API

Assigner: GitHub_M
Reserved: 13.05.2026 Published: 08.06.2026 Updated: 08.06.2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor FlowiseAI
Product Flowise
Versions
  • Version < 3.1.2 is affected

References

Problem Types

  • CWE-522: Insufficiently Protected Credentials CWE