Skip to content

MCPA-2026-0048

criticalcredential-leak

Flowise unauthenticated OAuth2 token refresh endpoint leaks access tokens (CVE-2026-70478)

Flowise 3.1.2 and earlier expose an unauthenticated OAuth2 token refresh endpoint that returns fresh access tokens for stored credentials, enabling token theft for any service connected to the instance. Fixed in 3.1.3.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.3

Identifiers

CVE-2026-70478GHSA-qgvm-j2hm-6m38CWE-200

References

Timeline

  • Published: 2026-08-04

← All advisories