Missing Authentication for Critical Function in Flowise - #VU126240

 

Missing Authentication for Critical Function in Flowise - #VU126240

Published: April 15, 2026


Vulnerability identifier: #VU126240
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authentication for a critical function in the /api/v1/loginmethod endpoint when handling GET requests with an organizationId parameter. A remote attacker can send a specially crafted request to disclose sensitive information.

The response can include OAuth client secrets in cleartext for an organization's configured SSO providers.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.0

External References

Related Security Bulletins