CVE-2026-73604: Flowise before 3.1.3 Credential Exposure via API
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73604?
The severity of CVE-2026-73604 is medium with a score of 6.5.
How do I fix CVE-2026-73604?
To fix CVE-2026-73604, upgrade Flowise to version 3.1.3 or later.
What type of vulnerability is CVE-2026-73604?
CVE-2026-73604 is an incomplete credential redaction vulnerability affecting the API.
What information can be exposed by CVE-2026-73604?
CVE-2026-73604 can expose sensitive data, including database connection URLs, in plaintext.
Who is affected by CVE-2026-73604?
Authenticated users with credentials:view permission in Flowise before version 3.1.3 are affected by CVE-2026-73604.