A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. Upgrading the affected component is recommended.
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
Problem type
Affected products
FlowiseAI
3.0.0 - AFFECTED
3.0.1 - AFFECTED
3.0.2 - AFFECTED
3.0.3 - AFFECTED
3.0.4 - AFFECTED
3.0.5 - AFFECTED
3.0.6 - AFFECTED
3.0.7 - AFFECTED
3.0.8 - AFFECTED
3.0.9 - AFFECTED
3.0.10 - AFFECTED
3.0.11 - AFFECTED
3.0.12 - AFFECTED
References
https://vuldb.com/vuln/361276
https://vuldb.com/vuln/361276/cti
https://vuldb.com/submit/777659
https://gist.github.com/YLChen-007/1d52497b0221835f99367be61612746b
GitHub Security Advisories
GHSA-jrmf-qwfm-2m6w
A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify...
https://github.com/advisories/GHSA-jrmf-qwfm-2m6wA vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. Upgrading the affected component is recommended.
https://nvd.nist.gov/vuln/detail/CVE-2026-8028
https://gist.github.com/YLChen-007/1d52497b0221835f99367be61612746b
https://vuldb.com/submit/777659
https://vuldb.com/vuln/361276
https://vuldb.com/vuln/361276/cti
https://github.com/advisories/GHSA-jrmf-qwfm-2m6w
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-8028Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-8028",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-05-06T14:35:31.158Z",
"dateReserved": "2026-05-06T07:40:41.272Z",
"datePublished": "2026-05-06T14:15:10.891Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-05-06T14:15:10.891Z"
},
"title": "FlowiseAI Flowise Endpoint account.service.ts verify information disclosure",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. Upgrading the affected component is recommended."
}
],
"affected": [
{
"vendor": "FlowiseAI",
"product": "Flowise",
"cpes": [
"cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*"
],
"modules": [
"Endpoint"
],
"versions": [
{
"version": "3.0.0",
"status": "affected"
},
{
"version": "3.0.1",
"status": "affected"
},
{
"version": "3.0.2",
"status": "affected"
},
{
"version": "3.0.3",
"status": "affected"
},
{
"version": "3.0.4",
"status": "affected"
},
{
"version": "3.0.5",
"status": "affected"
},
{
"version": "3.0.6",
"status": "affected"
},
{
"version": "3.0.7",
"status": "affected"
},
{
"version": "3.0.8",
"status": "affected"
},
{
"version": "3.0.9",
"status": "affected"
},
{
"version": "3.0.10",
"status": "affected"
},
{
"version": "3.0.11",
"status": "affected"
},
{
"version": "3.0.12",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Information Disclosure",
"cweId": "CWE-200",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Improper Access Controls",
"cweId": "CWE-284",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/361276",
"name": "VDB-361276 | FlowiseAI Flowise Endpoint account.service.ts verify information disclosure",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/361276/cti",
"name": "VDB-361276 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/submit/777659",
"name": "Submit #777659 | FlowiseAI Flowise <= 3.0.12 Exposure of Sensitive Information (CWE-200)",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://gist.github.com/YLChen-007/1d52497b0221835f99367be61612746b",
"tags": [
"exploit"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"baseScore": 3.7,
"baseSeverity": "LOW"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"baseScore": 3.7,
"baseSeverity": "LOW"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
"baseScore": 2.6
}
}
],
"timeline": [
{
"time": "2026-05-06T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-05-06T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-05-06T09:45:52.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "Eric-a (VulDB User)",
"type": "reporter"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-05-06T14:35:31.158Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}