Flowise fixed two closely related flaws in its OAuth2 credential refresh functionality that allowed unauthenticated access to POST /api/v1/oauth2-credential/refresh/:credentialId. In versions before 3.1.3, tracked as CVE-2026-70478, the endpoint was placed in WHITELIST_URLS without authentication, letting an attacker who knew a credential ID decrypt stored OAuth details, trigger a refresh with the provider, and receive the new access token in the response. The issue exposed connected third-party services to token theft and could also be abused to consume refresh-token quotas.
A follow-on bug, CVE-2026-70636, showed the earlier fix was incomplete and that Flowise through 3.1.4 still allowed authentication bypass through prefix-based whitelist matching. Researchers reported that crafted requests with a trailing credential identifier could still reach the refresh handler, which refreshed and updated OAuth credentials without validating caller identity, workspace ownership, or RBAC permissions. The flaw enabled cross-workspace token rotation and unauthorized mutation of credential state, and was described as a bypass of an earlier remediation tied to GHSA-6f7g-v4pp-r667.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record says disclosure@vulncheck.com received CVE-2026-70636, an authentication bypass affecting Flowise through version 3.1.4. The flaw allows crafted requests to the OAuth2 credential refresh endpoint to bypass authorization and trigger unauthorized token rotation.
The CVE record states that CVE-2026-70478, an unauthenticated OAuth2 token refresh flaw in Flowise, was received by security-advisories@github.com. The issue affects versions prior to 3.1.3 and can expose refreshed access tokens for connected services.
A CayCon advisory reported that Flowise 3.1.3 still allowed unauthenticated access to the OAuth2 credential refresh endpoint because prefix-based whitelist matching bypassed API key and JWT checks. The report says CayCon and piropatriot independently discovered and responsibly disclosed the issue, describing it as an incomplete remediation of an earlier fix.
Flowise addressed CVE-2026-70478 in version 3.1.3. The flaw involved the unauthenticated POST /api/v1/oauth2-credential/refresh/:credentialId endpoint being whitelisted and returning refreshed access tokens.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.