Summary
CVE-2026-70478 is a critical (CVSS 9.2) information-disclosure vulnerability in FlowiseAI’s Flowise, an open-source generative AI development platform. An unauthenticated OAuth2 token refresh endpoint returns freshly issued access tokens to any caller, allowing attackers to steal tokens for connected third-party services. It affects all Flowise versions up to and including 3.1.2.
Technical details
- Root cause: The endpoint
POST /api/v1/oauth2-credential/refresh/:credentialIdis included inWHITELIST_URLS, so it requires no authentication. It decrypts stored credentials and returns a newly issued OAuth2 access token directly in the response without verifying the requester’s identity (CWE-200). - Trigger conditions: An attacker obtains a credential ID (for example through public chatflow leaks or enumeration) and calls the refresh endpoint.
- Attack vector: Network — no authentication, privileges, or user interaction required.
- Impact: Theft of OAuth2 access tokens for connected services, exposure of client secrets during refresh operations, compromise of the victim’s integrated third-party accounts, and potential denial of service through refresh-token quota exhaustion.
Affected software
- Flowise (npm
flowise) versions ≤ 3.1.2.
Severity
- CVSS 4.0 base score: 9.2 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Mitigation and recommended actions
- Immediate: Upgrade to Flowise 3.1.3, which fixes the vulnerability.
- If no patch: Restrict network access to the Flowise instance to authenticated, authorized users only; block or require authentication in front of the
/api/v1/oauth2-credential/refresh/endpoint at a reverse proxy; and rotate any OAuth2 credentials that may have been exposed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Flowise - Build AI Agents, Visually,Flowise - Low-code LLM apps builder - Meta tag content — author:
FlowiseAI; description:Open source generative AI development platform for building AI agents - Raw response body:
data-rewardful="9a3a26",og:site_name,flowiseai.com

