Junglewise Threat Intelligence

CVE-2026-56267: Flowise information exposure in forgot-password endpoint

CVE-2026-56267 · Severity: medium · CVSS 4 · Published 2026-06-20

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a security flaw in its password reset feature. An unauthorized person can discover if a specific email address has an account and automatically retrieve the user's full name, internal ID, and account activity dates. This information can be used to harvest customer data or conduct targeted phishing attacks against your users.

Technical details

An information exposure vulnerability exists in the POST /api/v1/account/forgot-password endpoint of Flowise. The root cause is located in the account.service.ts file, where the forgotPassword method returns a sanitized user object instead of a generic success message. While the sanitization process removes authentication tokens and password hashes, it fails to strip other Personally Identifiable Information (PII). An unauthenticated remote attacker can send a request with a known email address to receive a JSON response containing the user's UUID, full name, account status, and creation/update timestamps. This allows for large-scale account enumeration and data harvesting. The issue is resolved in version 3.0.13.

Affected products

  • FlowiseAI Flowise < 3.0.13

Timeline

  • 2026-03-05: advisory: GitHub Security Advisory published
  • 2026-06-20: disclosed: NVD publication date

References

Related threats