OAuth2 Token Refresh Vulnerability in Flowise by FlowiseAI
CVE-2026-69250
8.5HIGH
What is CVE-2026-69250?
Flowise, a user-friendly interface for building customized language model flows, had a vulnerability prior to version 3.1.3 in the authentication process for its OAuth2 token refresh endpoint. Specifically, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint was accessible without authentication, allowing unauthorized users to trigger outbound requests to specified accessTokenUrl. This weakness led to the exposure of sensitive data, including client_id and client_secret, to an attacker-controlled server. This security flaw has been addressed in the updated version 3.1.3, which implements necessary authentication checks and mitigates the risk of such attacks.
Affected Version(s)
Flowise < 3.1.3
