CVE-2026-56272: Flowiseai Flowise

Medium severity, CVSS 4.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.

Affected products

  • Flowiseai Flowise: before 3.0.13 (fixed in 3.0.13)

Published 2026-06-24. Last modified 2026-06-26.