GitHub Security Advisory (GHSA-rwrp-9823-p2xq)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-rwrp-9823-p2xq CVE-2026-73604
HIGH
Flowise before 3.1.3 Credential Exposure via API
Record summary
CVE-2026-73604 has a selected CVSS score of 7.1 (high).
Description
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.3 | affected |
| 3.1.3 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73604 VulnCheck Advisory: Flowise before 3.1.3 Credential Exposure via APIThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-credential-exposure-via-api