Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 18, 2026 (about 4 months ago).

people · May 18, 2026

SentinelOne Reports CVE-2026-41275 Information Disclosure in Flowise Password Reset

Share the canonical public link.

Share as image

SentinelOne detailed CVE-2026-41275, an information disclosure flaw in Flowise on cloud.flowiseai.com. The vulnerability transmitted password reset links over unsecured HTTP instead of HTTPS, exposing credentials to man-in-the-middle attacks on public networks. Affected users could have reset links intercepted without authentication. The report referenced related HackerOne submission #1888915 and linked CVE-2026-41278 for additional exposure risks.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence