9.1
CVE-2026-46440
- EPSS 0.25%
- Veröffentlicht 08.06.2026 15:29:40
- Zuletzt bearbeitet 11.06.2026 04:06:33
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Flowise: Basic Auth Credentials Exposed via API
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.162 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| security-advisories@github.com | 7.5 | 1.6 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-php6-83fg-gw3g