Executive brief
Flowise uses a weak hard-coded default secret ('Secre$t') for token encryption when the TOKEN_HASH_SECRET environment variable is not set, potentially allowing token metadata manipulation.
Affected products
- npm flowise
Junglewise Threat Intelligence
Severity: medium · CVSS 5.6 · Published 2026-04-16
Technologies: flowise (npm). Vendors: npm.
Flowise uses a weak hard-coded default secret ('Secre$t') for token encryption when the TOKEN_HASH_SECRET environment variable is not set, potentially allowing token metadata manipulation.