CVE-2026-90534 | FlowiseAI Flowise up to 3.1.3 Credential Resolution /api/v1/node-load-method getCredentialData nodeName permission
A vulnerability was found in FlowiseAI Flowise up to 3.1.3. It has been rated as critical. This impacts the function getCredentialData of the file /api/v1/node-load-method of the component Credential Resolution. Performing a manipulation of the argument nodeName results in permission issues.
This vulnerability is reported as CVE-2026-90534. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More