people · May 18, 2026
SentinelOne Reports CVE-2026-41275 Information Disclosure in Flowise Password Reset
Share the canonical public link.
SentinelOne detailed CVE-2026-41275, an information disclosure flaw in Flowise on cloud.flowiseai.com. The vulnerability transmitted password reset links over unsecured HTTP instead of HTTPS, exposing credentials to man-in-the-middle attacks on public networks. Affected users could have reset links intercepted without authentication. The report referenced related HackerOne submission #1888915 and linked CVE-2026-41278 for additional exposure risks.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)