THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rwrp-9823-p2xq (medium) — Flowise: Incomplete Credential Redaction Exposes Secrets via API

[GHSA] GHSA-rwrp-9823-p2xq (medium) — Flowise: Incomplete Credential Redaction Exposes Secrets via API

highgithub_advisoriesPublished 2026-08-04

GHSA-rwrp-9823-p2xq Severity: medium CVE: None

Flowise: Incomplete Credential Redaction Exposes Secrets via API

## Summary

The `GET /api/v1/credentials/:id` endpoint decrypts stored credential data and returns it in the `plainDataObj` field of the API response. While a `redactCredentialWithPasswordType()` function masks fields defined with `type: 'password'` in their component schema, many cred

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rwrp-9823-p2xq