Missing Authentication for Critical Function in Flowise - #VU140070

 

Missing Authentication for Critical Function in Flowise - #VU140070

Published: July 30, 2026


Vulnerability identifier: #VU140070
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite OAuth2 tokens in any credential.

The vulnerability exists due to improper access control in the OAuth2 callback endpoint when processing callback requests with the state parameter used as a credential lookup key and no workspace scoping. A remote user can forge an OAuth2 callback request to overwrite OAuth2 tokens in any credential.

The callback endpoint is whitelisted from authentication, and exploitation requires control of an OAuth2 provider response or interception of the OAuth2 flow.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins