OAuth Credential Refresh Vulnerability in Flowise by FlowiseAI
CVE-2026-70478

9.2CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70478?

Flowise, a user-friendly interface for creating customized large language model flows, contains a serious vulnerability in versions prior to 3.1.3. Specifically, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is improperly configured, allowing unrestricted access without authentication. This flaw enables attackers to decrypt stored credentials and generate valid access tokens using the refresh token and client secret. Consequently, unauthorized users can exploit these tokens to gain access to connected services and potentially exhaust available refresh token quotas, posing significant security risks to affected users. The issue has been resolved in version 3.1.3.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.