| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m7mq-85xj-9x33 | Flowise: Weak Default Token Hash Secret |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives the AES-256-CBC key used to encrypt user IDs and workspace IDs in the 'meta' field of JWT tokens. An attacker who knows the default secret can decrypt this metadata to extract internal user and workspace identifiers, and re-encrypt manipulated values such as altered user or workspace IDs. Because the JWT signature is validated separately, decrypting or tampering with this metadata does not by itself grant access, but the disclosure of internal identifiers and possible metadata manipulation could aid privilege escalation or unauthorized data access. | |
| Title | Flowise - Weak Default Token Hash Secret in JWT Token Encryption | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-24T14:58:19.578Z
Reserved: 2026-06-20T01:47:54.000Z
Link: CVE-2026-56269
Updated: 2026-06-24T14:58:13.786Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T13:30:06Z
Github GHSA