CVE-2026-70478Critical· 10.0▾ MidnightFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.5%
10 → —
— → 10
10 → —
— → 10
10 → —
— → 10
10 → —
— → 10
10 → —
— → 10
10 → —
— → 10
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the refreshed access_token in the response body. An attacker with a credential ID can use the token to access the victim's connected service and can also exhaust refresh-token quota. This issue is fixed in 3.1.3.
flowise < 3.1.3Upgrade past the affected range:
flowise 3.1.3Affected packages:
flowise <= 3.1.2Patched in:
flowise 3.1.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70473High· 8.5Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows
GHSA-rwrp-9823-p2xqMedium· 6.5Flowise: Incomplete Credential Redaction Exposes Secrets via API
CVE-2026-73604Medium· 6.5Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2024-58351HighFlowise OverrideConfig security vulnerability
CVE-2026-70475Medium· 6.5Flowise is a drag & drop user interface to build a customized large language model flow