Junglewise Threat Intelligence

FlowiseAI sensitive information disclosure in credentials service

Severity: high · CVSS 7 · Published 2026-05-14

Technologies: flowise (npm). Vendors: npm.

Executive brief

FlowiseAI is vulnerable to a credential data leak when fetching credentials using a specific filter, exposing encrypted sensitive information to authenticated users.

Affected products

  • npm flowise

Related threats