CVE 7.5 HIGH

Flowise: Password Reset Link Sent Over Unsecured HTTP_CVE-2026-41275

7.5 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behavior introduces the risk of a man-in-the-middle (MITM) attack, where an attacker on the same network as the user (e.g., public Wi-Fi) can intercept the reset link and gain unauthorized access to the victim’s account. This vulnerability is fixed in 3.1.0.

Basic Information

ID CVE-2026-41275
Source GitHub_M
Published Apr 23, 2026 at 19:33

Affected Product

Vendor FlowiseAI
Product Flowise
Version < 3.1.0
Affected Versions FlowiseAI Flowise < 3.1.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.