CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-56278

Critical · CVSS 9.1

Flowise — Hardcoded Default Secret / Session Forgery Authentication Bypass

CVSS
9.1
nvd
EPSS
0.38%
30th pct
KEV
No
Class
other
CWE-798

Description

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacker can forge valid signed session cookies to impersonate any user and bypass authentication.

Search profile — drives PoC discovery

Symbols EXPRESS_SESSION_SECRETexpress-sessionflowisepassportpackages/server/src/enterprise/middleware/passport/index.tsexpress-session secretsession cookie forgery
Keywords CVE-2026-56278Flowise hardcoded secretFlowise session hijackingFlowise authentication bypassGHSA-2qqc-p94c-hxwhFlowise express-session weak secretFlowise forged session cookieFlowise 3.0.13 exploitFlowiseAI session forgery PoC
Versions: <= 3.0.13 (fixed in 3.1.0)

References

Status: enriched · ingested 2026-07-06T18:00:39.000Z · profiled 2026-07-06T18:30:39.000Z