CVE-2026-41275

7.5

FlowiseAI · Flowise

Flowise versions prior to 3.1.0 transmit password reset links over unsecured HTTP, exposing users to man-in-the-middle attacks that could result in account takeover.

Executive summary

Flowise contains a critical vulnerability involving cleartext transmission of sensitive reset tokens, which permits unauthorized account access via man-in-the-middle attacks.

Vulnerability

This vulnerability is classified as CWE-319, involving the transmission of sensitive password reset links over unencrypted HTTP. An attacker on the same network as the victim can intercept these links to compromise user accounts without requiring prior authentication.

Business impact

Successful exploitation allows an attacker to intercept password reset links, leading to complete account takeover. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to data confidentiality and integrity, potentially allowing unauthorized access to customized large language model flows and associated proprietary data.

Remediation

Immediate Action: Update the Flowise software to version 3.1.0 or later to ensure all sensitive communications are forced over HTTPS.

Proactive Monitoring: Review access logs for suspicious patterns originating from local network segments or unusual IP ranges, especially during password reset activities.

Compensating Controls: Enforce strict network security policies, such as the use of VPNs or encrypted tunnels, for all users accessing the Flowise interface until the update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: unknown).

Analyst recommendation

The risk of account takeover via unencrypted credential recovery is significant for all deployments of Flowise. Administrators must prioritize updating to version 3.1.0 immediately to remediate this cleartext transmission flaw and protect user accounts from interception attacks.

More FlowiseAI CVEs

Sources