CVE-2026-46440
Flowise is a drag‑and‑drop interface for building large‑language‑model flows. A flaw in the checkBasicAuth endpoint allowed attackers to compare credentials in plaintext without rate limiting, enabling brute‑force attacks. The issue is fixed in version 3.1.2.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Flowise version 3.1.1 and earlier (flowiseai flowise).
Real-world impact
An attacker could guess or brute‑force user credentials to gain unauthorized access to the Flowise interface, potentially exposing sensitive data or allowing further exploitation of the system.
Why this severity
The CVSS score of 9.1 reflects the lack of authentication and rate limiting, making it easy for attackers to guess passwords (attack vector network, low complexity, no privileges).
What to do about it
- 011. Upgrade Flowise to version 3.1.2 or later.
NVD-referenced vendor advisory
Timeline
- Jun 8, 2026 · Jun 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/FlowiseAI/Flowise/releases/…productrelease notes
- github.com/FlowiseAI/Flowise/security/…mitigationvendor advisory