MCPA-2026-0048
criticalcredential-leak
Flowise unauthenticated OAuth2 token refresh endpoint leaks access tokens (CVE-2026-70478)
Flowise 3.1.2 and earlier expose an unauthenticated OAuth2 token refresh endpoint that returns fresh access tokens for stored credentials, enabling token theft for any service connected to the instance. Fixed in 3.1.3.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, < 3.1.3 |
Identifiers
CVE-2026-70478GHSA-qgvm-j2hm-6m38CWE-200
References
- advisory https://github.com/advisories/GHSA-qgvm-j2hm-6m38
- advisory https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-qgvm-j2hm-6m38
- web https://nvd.nist.gov/vuln/detail/CVE-2026-70478
Timeline
- Published: 2026-08-04