Junglewise Threat Intelligence

Flowise hard-coded default secret in token encryption

Severity: medium · CVSS 5.6 · Published 2026-04-16

Technologies: flowise (npm). Vendors: npm.

Executive brief

Flowise uses a weak hard-coded default secret ('Secre$t') for token encryption when the TOKEN_HASH_SECRET environment variable is not set, potentially allowing token metadata manipulation.

Affected products

  • npm flowise

Related threats