CVE-2026-70478: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI Flowise
Flowise versions prior to 3.1.3 contain a vulnerability where the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is accessible without authentication. This endpoint decrypts stored OAuth credentials and returns refreshed access tokens, exposing sensitive information to unauthorized actors. An attacker with knowledge of a credential ID can obtain access tokens to connected services and potentially exhaust refresh-token quotas. The issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
In Flowise before version 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in a whitelist of URLs that do not require authentication. This endpoint decrypts stored OAuth credentials and uses them to request refreshed access tokens from the OAuth provider, returning the refreshed access token in the response. Because no authentication is required, an attacker who knows a credential ID can retrieve valid access tokens, gaining unauthorized access to the victim's connected services and potentially exhausting the refresh-token quota. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and has a CVSS 4.0 score of 9.2 (critical). The issue is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with knowledge of a credential ID can obtain valid OAuth access tokens without authentication, allowing unauthorized access to connected services. Additionally, the attacker can exhaust the refresh-token quota, potentially disrupting legitimate token refresh operations. This exposure of sensitive credentials poses a critical security risk.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed by requiring proper authentication for the affected endpoint. No other mitigations are indicated by the vendor advisory.
CVE-2026-70478: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI Flowise
Description
Flowise versions prior to 3.1.3 contain a vulnerability where the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is accessible without authentication. This endpoint decrypts stored OAuth credentials and returns refreshed access tokens, exposing sensitive information to unauthorized actors. An attacker with knowledge of a credential ID can obtain access tokens to connected services and potentially exhaust refresh-token quotas. The issue is fixed in version 3.1.3.
CVSS v4.0
Score 9.2critical
Affected software
FlowiseAI
Flowise
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Flowise before version 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in a whitelist of URLs that do not require authentication. This endpoint decrypts stored OAuth credentials and uses them to request refreshed access tokens from the OAuth provider, returning the refreshed access token in the response. Because no authentication is required, an attacker who knows a credential ID can retrieve valid access tokens, gaining unauthorized access to the victim's connected services and potentially exhausting the refresh-token quota. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and has a CVSS 4.0 score of 9.2 (critical). The issue is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with knowledge of a credential ID can obtain valid OAuth access tokens without authentication, allowing unauthorized access to connected services. Additionally, the attacker can exhaust the refresh-token quota, potentially disrupting legitimate token refresh operations. This exposure of sensitive credentials poses a critical security risk.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed by requiring proper authentication for the affected endpoint. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-04T15:24:41.339Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a724791bf8831d5396138e5
Added to database: 08/04/2026, 20:12:01 UTC
Last enriched: 08/12/2026, 15:11:41 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 158
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.