External risk intelligence

Flowise Cloud Cross-Tenant Secrets Exposure

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2025-59434

The vulnerability affects a cloud-hosted service accessible by users on the public internet. As a managed cloud platform, the service is designed for public access and interaction, making the vulnerable interface and its underlying cross-tenant functionality exposed by design.

Information Disclosure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Flowise Cloud allows any user on the free tier to access sensitive environment variables, such as API keys and cloud credentials, belonging to other users. This could lead to significant data exposure across different tenants. The issue has been addressed in an August 2025 update.

  • Unauthenticated access to other users' secrets.
  • Cloud platform data exposure across tenants.
  • Confirm platform relevance and exposure.

Attack Path

How an attacker could exploit the issue

A user on the free tier of cloud-hosted Flowise could potentially access sensitive information belonging to other users. This is possible by exploiting a vulnerability within the Custom JavaScript Function node, which allows for cross-tenant data exposure of secrets like API keys and cloud credentials.

  • Entry condition: Authenticated free-tier user.
  • Trigger point: Custom JavaScript Function node.
  • Resulting risk: Sensitive cross-tenant data exposure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in cloud-hosted Flowise could allow any user on the free tier to access sensitive environment variables from other tenants. When supported by the advisory, this exposure could include secrets such as API keys and cloud credentials, leading to full cross-tenant data exposure.

  • Sensitive cloud credentials at risk.
  • Access via Custom JavaScript Function node.
  • Full cross-tenant data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

For cloud-hosted Flowise instances, platform or infrastructure teams managing the Flowise service are likely responsible for addressing this vulnerability, with vendor coordination being crucial if it's a third-party SaaS offering. The immediate priority is to confirm if any Flowise instances are currently exposed and assess the business criticality of any affected tenants, especially those on the free tier, before planning remediation.

  • Identify affected Flowise instances and tenants.
  • Verify tenant data access and business criticality.
  • Coordinate with the vendor for tenant-level mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a platform featuring a drag-and-drop interface that simplifies the creation of custom workflows for large language models. It is commonly used by developers and businesses to integrate various AI services and cloud components into automated flows without needing to code every connection from scratch.

What does CWE-200 and CWE-284 mean for CVE-2025-59434?

These codes identify the nature of the security flaw. CWE-200 refers to an exposure of sensitive information, while CWE-284 relates to improper access control. In this CVE, these weaknesses allowed an authenticated user to bypass logical boundaries, enabling them to read secret environment variables belonging to other tenants on the same platform.

How is the Custom JavaScript Function node triggered?

The vulnerability is triggered when a user utilizes the Custom JavaScript Function node within the platform. It is important to note that this is not an unauthenticated attack; it requires an active, authenticated account on the free tier of the service to interact with the node and access restricted data from other users.

Why does Halo Surface Signal categorize this as an external risk?

Halo Surface Signal flags this as an external risk because Flowise Cloud is a managed service designed for public internet access. Since the platform is built to be reachable by users globally, the cross-tenant vulnerability was effectively exposed by the service's design, making it accessible to anyone with a valid free-tier account.

Do I need to take action if I use Flowise Cloud?

If you were using the cloud-hosted version before the August 2025 patch, you should verify the security of your stored environment variables. Check your current API keys, AWS credentials, or other cloud secrets for any signs of unauthorized use, as they may have been accessible to other tenants on the free tier before the fix was implemented.

References