Impact
The verify function in the account.service.ts of Flowise’s Endpoint component can be manipulated to expose sensitive data. The flaw allows remote callers to retrieve information that should not be disclosed, and although the attack requires high complexity and is described as difficult, the exploit is already public.
Affected Systems
FlowiseAI Flowise versions up to and including 3.0.12 are vulnerable. The affected component is the Endpoint service used for account verification. Any deployment of Flowise running these versions may expose confidential data if the verification endpoint is reachable from outside the trusted network.
Risk and Exploitability
The CVSS score of 6.3 places this vulnerability in the moderate range. EPSS score is <1%, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can target the endpoint remotely; the high attack complexity and difficulty of exploitation suggest that successful compromise is not trivial, but the existence of a public exploit increases the risk to exposed systems.
OpenCVE Enrichment