Junglewise Threat Intelligence

Flowise unauthenticated OAuth secret disclosure in loginmethod API

Severity: medium · CVSS 5.3 · Published 2026-04-16

Technologies: flowise (npm). Vendors: npm.

Executive brief

Flowise allows unauthenticated users to retrieve sensitive OAuth credentials and SSO configurations in cleartext via the /api/v1/loginmethod endpoint.

Affected products

  • npm flowise

Related threats