CVE-2026-46440
9.1 CRITICALFlowise is a drag & drop user interface to build a customized large language model flow
Published: 2026-06-08 · Last updated: 2026-06-11
Severity and scoring
- CVSS
- 9.1 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CWE
- CWE-522
Affected products
| Vendor | Product |
|---|---|
| flowiseai | flowise |
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-46440
- [Other]https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2
- [Vendor advisory]https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-php6-83fg-gw3g
- [Vendor advisory]https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-php6-83fg-gw3g
Related CVEs
Same vendor
- CVE-2026-46480 — Flowise is a drag & drop user interface to build a customized large language model flow (8.8 HIGH)
- CVE-2026-46444 — Flowise is a drag & drop user interface to build a customized large language model flow (8.8 HIGH)
- CVE-2026-46443 — Flowise is a drag & drop user interface to build a customized large language model flow (6.5 MEDIUM)
- CVE-2026-46442 — Flowise is a drag & drop user interface to build a customized large language model flow (9.9 CRITICAL)
- CVE-2026-46441 — Flowise is a drag & drop user interface to build a customized large language model flow (9.6 CRITICAL)
Same CWE
- CVE-2026-41715 — In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials (6.1 MEDIUM)
- CVE-2026-39908 — OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the N... (6.5 MEDIUM)
- CVE-2026-46511 — HAX CMS helps manage microsite universe with PHP or NodeJs backends
- CVE-2026-7313 — CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote a... (8.7 HIGH)
- CVE-2026-7312 — CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 t... (10.0 CRITICAL)