Skip to content
FlowiseGHSA-8f47-4rh3-x44m

Flowise: Bcrypt Password Hash Exposure

Medium3.7CVE-2026-8026 · Published May 6, 2026 · updated May 12, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
<= 3.0.12No fix yet
Details and references

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. You should upgrade the affected component.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200, CWE-312
Also known as
CVE-2026-8026

More Flowise advisories

All Flowise

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.