THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wch5-xp77-fxg4 (high) — Flowise: Cross-Workspace OAuth2 Credential Metadata Leak

[GHSA] GHSA-wch5-xp77-fxg4 (high) — Flowise: Cross-Workspace OAuth2 Credential Metadata Leak

highgithub_advisoriesPublished 2026-08-04

GHSA-wch5-xp77-fxg4 Severity: high CVE: CVE-2026-70474

Flowise: Cross-Workspace OAuth2 Credential Metadata Leak

## Summary

Three OAuth2 credential endpoints look up credentials by `id` alone with no `workspaceId` filter. Two of these endpoints (`callback`, `refresh`) are whitelisted from all authentication. This allows:

1. **Cross-workspace credential access** — Any authenticated user can init

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wch5-xp77-fxg4