Zurück zur CVE-Übersicht
CVE-2026-46440
CRITICAL(9.1)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Risk Signal Score28/100 — MITTEL
- CVSS 9.1 — Kritisch
EPSS-Score
0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.1
Technische Schwere
Beschreibung
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.
GitHub Advisories
GHSA-php6-83fg-gw3gHIGH
FlowiseAI Exposes Basic Auth Credentials via API
npm/flowise→ 3.1.2
GitHub Advisory