PT-2026-67728 · Flowise · Flowise
CVE-2026-69250
·
Published
2026-04-28
·
Updated
2026-08-04
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.3
Description
An unauthenticated endpoint
POST /api/v1/oauth2-credential/refresh/:credentialId allows for Server-Side Request Forgery (SSRF), a condition where the server is tricked into making requests to an unintended destination. The endpoint performs a server-side HTTP request to a user-controlled accessTokenUrl without proper protections. This allows an attacker to trigger outbound POST requests to an external or internal server, resulting in the exfiltration of sensitive data including client id, client secret, and refresh token within the request body. Additionally, the full response from the remote server is reflected back to the caller through the tokenInfo variable, confirming a non-blind SSRF.Recommendations
Update Flowise to version 3.1.3.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise