CVE-2026-46443
EUVD-2026-3511108.06.2026, 16:16
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response. The code properly omits encryptedData when no filter is used but fails to do so when a filter is used. This issue has been patched in version 3.1.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flowiseai | flowise | 𝑥 < 3.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration