Flowise - Weak Default JWT Secrets in Authentication Middleware
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.3epss 0.7%
from disclosure to weapon
Published on NVDJul 12
VulnCheck+71d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
yesVulnCheck
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Flowise · Flowise