Training data and privacy
Leakage of personal or proprietary data through training, memorization, inference attacks or careless logging.
- All items
- 19
- Last 90 days
- 5
- Change
- -17%vs 6 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 0 |
| Sep 2025 | 1 |
| Oct 2025 | 2 |
| Nov 2025 | 0 |
| Dec 2025 | 0 |
| Jan 2026 | 1 |
| Feb 2026 | 1 |
| Mar 2026 | 2 |
| Apr 2026 | 2 |
| May 2026 | 2 |
| Jun 2026 | 2 |
| Jul 2026 | 2 |
| Aug 2026 | 2 |
| Sep 2026 | 0 |
| Oct 2026 | 1 |
2 items
GHSA-4jpm-cgx2-8h37: Flowise: Sensitive Data Leak in public-chatbotConfig
Apr 16, 2026HighVulnerabilitySecurityPrivacyThe /api/v1/public-chatbotConfig/:id endpoint in Flowise returns the full flowData object without authentication or sanitization, through the getSinglePublicChatbotConfig function in packages/server/src/services/chatflows/index.ts. An attacker who knows only a chatflow UUID, which can be obtained from embedded chat widgets, referrer headers or logs, can retrieve plaintext password-type fields such as unstructuredAPIKey and HTTP Authorization headers. The impact covers all Flowise Cloud users with such chatflows and self-hosted instances exposed to the internet.
GitHub Advisory DatabaseCVE-2024-5206: scikit-learn TfidfVectorizer leaks sensitive training tokens via stop_words_
Jun 6, 2024MediumVulnerabilitySecurityPrivacyCVE-2024-5206CVE-2024-5206 affects scikit-learn's TfidfVectorizer in versions up to and including 1.4.1.post1. The vectorizer stores every token from the training data in its `stop_words_` attribute, not only the tokens TF-IDF needs, so tokens meant to be discarded, such as passwords or keys, can be exposed. The impact depends on the data the vectorizer processes.
Fix: Fixed in 1.5.0
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.