CVE-2025-59434

9.6

FlowiseAI · Flowise Cloud

A cross-tenant data exposure vulnerability in Flowise Cloud allows authenticated users to access sensitive environment variables and secrets from other tenants via the Custom JavaScript Function node.

Executive summary

An authenticated vulnerability in Flowise Cloud allows unauthorized access to sensitive tenant secrets, posing a critical risk of cross-tenant data exposure.

Vulnerability

This flaw involves improper access control (CWE-284) and exposure of sensitive information (CWE-200), where any authenticated user on the free tier can leverage the Custom JavaScript Function node to extract secrets from other tenants.

Business impact

The exploitation of this vulnerability leads to a total compromise of sensitive environment variables, including OpenAI API keys, AWS credentials, Supabase tokens, and Google Cloud secrets. With a CVSS score of 9.6, this represents a critical risk of unauthorized access to backend infrastructure and third-party services, potentially resulting in significant financial and data security breaches across the entire organization.

Remediation

Immediate Action: Ensure that all Flowise Cloud instances are updated to the August 2025 version or later, as the vendor has implemented a fix for this cross-tenant isolation issue.

Proactive Monitoring: Review access logs for any suspicious or unauthorized usage of the Custom JavaScript Function node by standard users.

Compensating Controls: Restrict the use of the Custom JavaScript Function node to trusted administrative accounts until the environment is fully verified as patched.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity score of 9.6 and the potential for total credential theft, organizations using the Flowise Cloud platform must prioritize this update immediately. Failure to remediate allows any authenticated user the potential to pivot into broader cloud infrastructure, making rapid deployment of the August 2025 patch the only effective path to securing your environment.

More FlowiseAI CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written

Sources