PT-2026-51775 · Flowise · Flowise
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.0
Description
A missing authentication issue exists in the '/api/v1/loginmethod' endpoint. Unauthenticated users can retrieve an organization's complete Single Sign-On (SSO) configuration, including OAuth client secrets in cleartext, by providing the
organizationId parameter. This allows remote attackers to harvest sensitive API credentials for integrations with Google, Microsoft/Azure, GitHub, and Auth0. This issue affects both FlowiseAI Cloud and self-hosted instances where the endpoint is exposed.Recommendations
Update to version 3.1.0 or later.
As a temporary workaround, restrict access to the '/api/v1/loginmethod' endpoint to minimize the risk of exploitation.
Exploit
Fix
DoS
Cleartext Storage of Sensitive Information
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowise