CVE-2026-70478: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI Flowise
Flowise versions prior to 3.1.3 contain a vulnerability where an unauthenticated endpoint allows exposure of sensitive OAuth credentials. The POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is accessible without authentication and returns refreshed access tokens, enabling attackers with a credential ID to access connected services and exhaust refresh-token quotas. This issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
Flowise before version 3.1.3 includes the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint in a whitelist that requires no authentication. This endpoint decrypts stored OAuth credentials and returns refreshed access tokens in the response. An attacker who knows a credential ID can exploit this to obtain access tokens and potentially access the victim's connected services or exhaust refresh-token quotas. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and has a CVSS 4.0 score of 9.2, indicating critical severity. The issue is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with knowledge of a valid credential ID can retrieve refreshed OAuth access tokens without authentication, potentially gaining unauthorized access to connected services. Additionally, the attacker can exhaust the refresh-token quota, potentially disrupting legitimate token refresh operations. This exposure of sensitive information compromises confidentiality and availability of OAuth credentials and connected services.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed. Since the vendor advisory indicates the issue is resolved in 3.1.3, applying this official fix is the recommended remediation. No other mitigation steps are indicated.
CVE-2026-70478: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI Flowise
Description
Flowise versions prior to 3.1.3 contain a vulnerability where an unauthenticated endpoint allows exposure of sensitive OAuth credentials. The POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is accessible without authentication and returns refreshed access tokens, enabling attackers with a credential ID to access connected services and exhaust refresh-token quotas. This issue is fixed in version 3.1.3.
CVSS v4.0
Score 9.2critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Flowise before version 3.1.3 includes the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint in a whitelist that requires no authentication. This endpoint decrypts stored OAuth credentials and returns refreshed access tokens in the response. An attacker who knows a credential ID can exploit this to obtain access tokens and potentially access the victim's connected services or exhaust refresh-token quotas. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and has a CVSS 4.0 score of 9.2, indicating critical severity. The issue is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with knowledge of a valid credential ID can retrieve refreshed OAuth access tokens without authentication, potentially gaining unauthorized access to connected services. Additionally, the attacker can exhaust the refresh-token quota, potentially disrupting legitimate token refresh operations. This exposure of sensitive information compromises confidentiality and availability of OAuth credentials and connected services.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed. Since the vendor advisory indicates the issue is resolved in 3.1.3, applying this official fix is the recommended remediation. No other mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-04T15:24:41.339Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a724791bf8831d5396138e5
Added to database: 08/04/2026, 20:12:01 UTC
Last enriched: 08/04/2026, 20:26:23 UTC
Last updated: 08/04/2026, 20:30:24 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.