CVE-2026-41275 Details
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behavior introduces the risk of a man-in-the-middle (MITM) attack, where an attacker on the same network as the user (e.g., public Wi-Fi) can intercept the reset link and gain unauthorized access to the victim’s account. This vulnerability is fixed in 3.1.0.
A vulnerability exists in Flowise versions prior to 3.1.0, where the password reset functionality on cloud.flowiseai.com transmits reset links over an unsecured HTTP connection instead of HTTPS. This flaw exposes users to potential man-in-the-middle (MITM) attacks, allowing attackers on the same network to intercept the reset link and gain unauthorized access to the user's account.
Users are advised to ensure that all password reset links are sent over HTTPS. Flowise has released a patch in version 3.1.0 that addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x5w6-38gp-mrqh | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x5w6-38gp-mrqh | [email protected] | ExploitMitigationVendor Advisory |
| https://hackerone.com/reports/1888915 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| flowiseai flowise | < 3.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 23, 2026 | New CVE Received | [email protected] |