Junglewise Threat Intelligence

FlowiseAI insufficient credential protection in basic auth endpoint

Severity: high · CVSS 7.5 · Published 2026-05-14

Technologies: FlowiseAI, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

FlowiseAI is vulnerable to credential brute-forcing and timing attacks due to insufficient protection of the basic authentication endpoint.

Affected products

  • FlowiseAI FlowiseAI
  • npm flowise

Related threats