CVE-2026-41278 | FlowiseAI Flowise up to 3.0.x :id sanitizeFlowDataForPublicEndpoint information disclosure (GHSA-w47f-j8rh-wx87 / WID-SEC-2026-1145)
A vulnerability identified as problematic has been detected in FlowiseAI Flowise up to 3.0.x. Impacted is the function sanitizeFlowDataForPublicEndpoint of the file /api/v1/public-chatflows/:id. This manipulation causes information disclosure.
This vulnerability is handled as CVE-2026-41278. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.