CVE-2026-56272: Flowiseai Flowise
Medium severity, CVSS 4.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.
Affected products
- Flowiseai Flowise: before 3.0.13 (fixed in 3.0.13)
Published 2026-06-24. Last modified 2026-06-26.