Executive brief
Flowise is an open-source platform for building AI agents and chatbots. An unauthenticated API endpoint exposes sensitive configuration data including API keys, authentication tokens, and internal webhook URLs without any access controls. An attacker who obtains a chatflow identifier (publicly available from embedded chat widgets or logs) can retrieve plaintext credentials and authentication headers, enabling account takeover and unauthorized access to integrated services.
Technical details
The /api/v1/public-chatbotConfig/:id endpoint in Flowise contains an information disclosure vulnerability (CWE-200, CWE-522, CWE-862) in the getSinglePublicChatbotConfig function located in packages/server/src/services/chatflows/index.ts. The function returns the complete flowData object without authorization checks or sensitive data sanitization, despite a misleading code comment claiming the endpoint is safe. An attacker with knowledge of a chatflow UUID (easily obtained from embedded chat widgets, HTTP referrer headers, or application logs) can make an unauthenticated network request to retrieve plaintext API keys stored in password-type fields (e.g., unstructuredAPIKey in S3File nodes), HTTP Authorization headers from POST/GET Request nodes, and internal API endpoints and webhook URLs. No user interaction or prior privilege level is required. The vulnerability affects all Flowise Cloud users and self-hosted instances exposed to the internet running versions 3.0.13 and earlier; a patch is available in version 3.1.0.
Affected products
- FlowiseAI Flowise <=3.0.13
Timeline
- 2026-04-16: disclosed
- 2026-04-16: patched: Fixed in version 3.1.0