OAuth Credential Refresh Vulnerability in Flowise by FlowiseAI
CVE-2026-70478
9.2CRITICAL
What is CVE-2026-70478?
Flowise, a user-friendly interface for creating customized large language model flows, contains a serious vulnerability in versions prior to 3.1.3. Specifically, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is improperly configured, allowing unrestricted access without authentication. This flaw enables attackers to decrypt stored credentials and generate valid access tokens using the refresh token and client secret. Consequently, unauthorized users can exploit these tokens to gain access to connected services and potentially exhaust available refresh token quotas, posing significant security risks to affected users. The issue has been resolved in version 3.1.3.
Affected Version(s)
Flowise < 3.1.2
