CVE-2026-56278
Critical · CVSS 9.1Flowise — Hardcoded Default Secret / Session Forgery Authentication Bypass
- CVSS
- 9.1
- nvd
- EPSS
- 0.38%
- 30th pct
- KEV
- No
- Class
- other
- CWE-798
Description
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacker can forge valid signed session cookies to impersonate any user and bypass authentication.
Search profile — drives PoC discovery
Symbols EXPRESS_SESSION_SECRETexpress-sessionflowisepassportpackages/server/src/enterprise/middleware/passport/index.tsexpress-session secretsession cookie forgery
Keywords CVE-2026-56278Flowise hardcoded secretFlowise session hijackingFlowise authentication bypassGHSA-2qqc-p94c-hxwhFlowise express-session weak secretFlowise forged session cookieFlowise 3.0.13 exploitFlowiseAI session forgery PoC
Versions: <= 3.0.13 (fixed in 3.1.0)
References
Status: enriched · ingested 2026-07-06T18:00:39.000Z · profiled 2026-07-06T18:30:39.000Z