Flowise Credential Data Leak Vulnerability

Vulnerability

A vulnerability in Flowise prior to version 3.1.2 allows authenticated users to access unredacted encrypted credential data, such as API keys and tokens, when using the 'credentialName' filter parameter. This data leak occurs because the 'encryptedData' field is not properly omitted from the response when the filter is applied, despite the code correctly excluding it when no filter is used. The issue has been patched in version 3.1.2.

Impact

Exploitation of this vulnerability allows for the extraction of encrypted credential data, including API keys, passwords, and service tokens. If the encryption key file is accessible, this enables full credential theft.

Reproduction

To reproduce this vulnerability, send a request to the Flowise API credentials endpoint with the 'credentialName' filter parameter. The response will include the 'encryptedData' field containing AES-encrypted credentials, such as OpenAI API keys, despite the expectation that this data should be omitted when the filter is used.

Remediation

Users can update to Flowise version 3.1.2, where this vulnerability has been fixed.

Added: Jun 8, 2026, 4:50 PM
Updated: Jun 8, 2026, 4:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.6
exploitability
6.2
remediation
7.7
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.