What is CVE-2026-73604?
CVE-2026-73604 is an incomplete credential redaction vulnerability in Flowise versions before 3.1.3, exposing decrypted secrets via the GET /api/v1/credentials/:id endpoint. Authenticated users with 'credentials:view' permission can retrieve sensitive data, such as database connection URLs with embedded passwords, in plaintext. Upgrading to version 3.1.3 or later is strongly recommended.
Azərbaycanca: CVE-2026-73604 Flowise 3.1.3-dən əvvəlki versiyalarda "credential redaction" mexanizminin natamam işləməsi ilə bağlı zəiflikdir. Bu, autentifikasiya olunmuş istifadəçilərə GET /api/v1/credentials/:id sorğusu vasitəsilə verilənlər bazası bağlantı URL-ləri kimi şifrələnmiş həssas məlumatları açıq mətn şəklində əldə etməyə imkan verir. Flowise proqramını 3.1.3 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Flowise are affected by CVE-2026-73604?
CVE-2026-73604 affects Flowise versions before 3.1.3.
What sensitive data can an authenticated user retrieve in plaintext through this vulnerability?
An authenticated user can retrieve sensitive data such as database connection URLs with embedded passwords in plaintext via the GET /api/v1/credentials/:id endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.