Junglewise Threat Intelligence

CVE-2026-41273: Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise

CVE-2026-41273 · Severity: high · CVSS 8.2 · Published 2026-04-16

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is a platform for building AI-powered conversational workflows that allows organizations to deploy public chatbots. An unauthenticated attacker can exploit two missing authentication checks to obtain OAuth 2.0 access tokens for third-party services (like Gmail) configured within the platform. This could enable unauthorized access to connected accounts, data breaches, or API abuse on behalf of the organization.

Technical details

Flowise contains an authentication bypass involving two chained API endpoints: GET /api/v1/public-chatbotConfig/<chatflowId> returns internal flowData without authentication, exposing OAuth credential identifiers; POST /api/v1/oauth2-credential/refresh/<credentialId> refreshes OAuth 2.0 tokens without authentication or authorization checks. An attacker can retrieve the credential identifier from the first endpoint and use it with the second endpoint to obtain valid OAuth 2.0 access tokens. This affects self-hosted deployments because public chatflows are intentionally exposed to unauthenticated users via public URLs. The vulnerability is mitigated in version 3.1.0 and later.

Affected products

  • FlowiseAI Flowise <=3.0.13

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: patched: Version 3.1.0 patches the vulnerability

References

Related threats