CVE-2026-69250: CWE-639: Authorization Bypass Through User-Controlled Key in FlowiseAI Flowise
Flowise versions prior to 3.1.3 contain an authorization bypass vulnerability in the OAuth2 token refresh endpoint. This endpoint is unauthenticated by design and allows an attacker to trigger server-side HTTP requests to attacker-controlled URLs without SSRF protections. Sensitive OAuth2 credentials are sent in these requests, and the full remote response is reflected back to the caller. The issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
CVE-2026-69250 describes an authorization bypass vulnerability (CWE-639) in Flowise before version 3.1.3. The OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is accessible without authentication and performs server-side HTTP requests to the accessTokenUrl controlled by the credential. There are no server-side request forgery (SSRF) protections, allowing attackers to control the outbound request destination. The endpoint sends sensitive OAuth2 parameters including client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body to the attacker-controlled server. The full response body from the remote server is reflected back to the caller via the tokenInfo response. This vulnerability enables unauthorized access to sensitive OAuth2 credentials and potentially sensitive data. The vulnerability is resolved in Flowise version 3.1.3.
Potential Impact
An attacker can exploit the unauthenticated OAuth2 token refresh endpoint to cause the server to send sensitive OAuth2 credentials to an attacker-controlled server. This can lead to unauthorized access to OAuth2 tokens and potentially compromise authentication flows. The reflection of the full remote response body to the attacker allows information disclosure. The vulnerability is rated high severity with a CVSS 4.0 score of 8.5.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed. Prior versions are vulnerable due to the unauthenticated token refresh endpoint and lack of SSRF protections. No other mitigations are stated in the vendor advisory.
CVE-2026-69250: CWE-639: Authorization Bypass Through User-Controlled Key in FlowiseAI Flowise
Description
Flowise versions prior to 3.1.3 contain an authorization bypass vulnerability in the OAuth2 token refresh endpoint. This endpoint is unauthenticated by design and allows an attacker to trigger server-side HTTP requests to attacker-controlled URLs without SSRF protections. Sensitive OAuth2 credentials are sent in these requests, and the full remote response is reflected back to the caller. The issue is fixed in version 3.1.3.
CVSS v4.0
Score 8.5high
Affected software
FlowiseAI
Flowise
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-69250 describes an authorization bypass vulnerability (CWE-639) in Flowise before version 3.1.3. The OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is accessible without authentication and performs server-side HTTP requests to the accessTokenUrl controlled by the credential. There are no server-side request forgery (SSRF) protections, allowing attackers to control the outbound request destination. The endpoint sends sensitive OAuth2 parameters including client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body to the attacker-controlled server. The full response body from the remote server is reflected back to the caller via the tokenInfo response. This vulnerability enables unauthorized access to sensitive OAuth2 credentials and potentially sensitive data. The vulnerability is resolved in Flowise version 3.1.3.
Potential Impact
An attacker can exploit the unauthenticated OAuth2 token refresh endpoint to cause the server to send sensitive OAuth2 credentials to an attacker-controlled server. This can lead to unauthorized access to OAuth2 tokens and potentially compromise authentication flows. The reflection of the full remote response body to the attacker allows information disclosure. The vulnerability is rated high severity with a CVSS 4.0 score of 8.5.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed. Prior versions are vulnerable due to the unauthenticated token refresh endpoint and lack of SSRF protections. No other mitigations are stated in the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.852Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a71fdb7bf8831d539fada1b
Added to database: 08/04/2026, 14:56:55 UTC
Last enriched: 08/11/2026, 18:07:27 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 41
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.