Junglewise Threat Intelligence

CVE-2026-56270: Flowise missing authentication in loginmethod API endpoint

CVE-2026-56270 · Severity: high · CVSS 7.5 · Published 2026-06-24

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a vulnerability that allows anyone on the internet to view sensitive login configuration details. An attacker can retrieve private credentials, such as OAuth client secrets for Google, Microsoft, and GitHub, without needing a password. This could allow unauthorized access to an organization's third-party integrations and lead to data breaches.

Technical details

A missing authentication vulnerability (CWE-306) exists in the /api/v1/loginmethod endpoint of Flowise. By sending a simple GET request with a target organizationId, an unauthenticated attacker can retrieve the full SSO configuration for that organization. The server response includes sensitive OAuth credentials, such as Client Secrets for Azure, Google, Auth0, and GitHub, stored and transmitted in cleartext (CWE-312). This issue affects Flowise versions up to 3.0.13 and has been patched in version 3.1.0.

Affected products

  • FlowiseAI flowise <= 3.0.13

Timeline

  • 2026-04-15: disclosed
  • 2026-04-16: advisory: GitHub Advisory published
  • 2026-04-16: patched: Version 3.1.0 released

References

Related threats