CVE-2026-56271

flowise: Use of Hard-coded Cryptographic Key (CVE-2026-56271)

criticalEPSS 0.7%

Description

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

npmflowise

Metrics

9.8
Source: nvd-v3
49.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-12 12:16 UTC
CWE-321

Weakness classes (CWE)

  • CWE-321Variant

    Use of Hard-coded Cryptographic Key

    The product uses a hard-coded, unchangeable cryptographic key.

    cwe.mitre.org →

References & sources

Linked advisories