Authenticated Vulnerability in Flowise Cloud Affects Drag & Drop User Interface
CVE-2025-59434
What is CVE-2025-59434?
Flowise Cloud, a customizable drag-and-drop interface for building large language model flows, experienced a security issue allowing users on the free tier to access sensitive environment variables of other tenants. This vulnerability, linked to the Custom JavaScript Function node, could expose critical secrets such as OpenAI API keys, AWS credentials, Supabase tokens, and Google Cloud secrets, leading to severe data exposure risks across tenants. This issue has been resolved in the August 2025 release of Flowise Cloud.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Flowise < cloud-hosted (as of Aug 2025)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
