Executive brief
Flowise is a workflow automation and AI application builder. The password reset functionality sends reset links over unencrypted HTTP instead of HTTPS, allowing attackers on the same network (such as public Wi-Fi) to intercept password reset tokens and hijack user accounts without additional authentication.
Technical details
The vulnerability is a failure to use HTTPS for sensitive password reset URLs (CWE-319). The root cause is that cloud.flowiseai.com generates password reset email links using HTTP protocol instead of HTTPS. An attacker positioned on the same network as the victim (e.g., via ARP spoofing or DNS hijacking on public Wi-Fi) can perform a man-in-the-middle attack to intercept the plaintext reset link and extract the reset token. The attack requires the attacker to be on the same network and the user to click the insecure link, but no prior authentication or privileges are needed. Exploitation allows complete account takeover. The vulnerability is fixed in version 3.1.0; all versions prior to 3.0.13 are affected.
Affected products
- FlowiseAI Flowise <=3.0.13
Timeline
- 2026-04-16: disclosed
- 2026-04-16: patched: Fix available in version 3.1.0