Skip to content

MCPA-2026-0056

highauth-missingCVSS 7.5

Flowise unauthenticated OAuth2 credential refresh via prefix-based whitelist bypass (CVE-2026-70636)

Flowise through 3.1.4: the authentication middleware whitelist uses prefix matching, so a POST to the oauth2-credential refresh route with a trailing credential identifier bypasses all authentication and authorization, letting unauthenticated attackers trigger OAuth token rotation for credentials in any workspace (a bypass of the CVE-2026-41273 fix). No fixed release: Flowise announced its sunset; through 3.1.4 (latest) remains affected.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, <= 3.1.4

Identifiers

CVE-2026-70636GHSA-rm9r-9424-cccfCWE-862

References

Timeline

  • Published: 2026-08-07

← All advisories