THREAT OPS › Threat News › [GHSA] GHSA-qgvm-j2hm-6m38 (critical) — Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
[GHSA] GHSA-qgvm-j2hm-6m38 (critical) — Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
GHSA-qgvm-j2hm-6m38 Severity: critical CVE: CVE-2026-70478
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
### Summary
The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is in `WHITELIST_URLS`, meaning it requires **no authentication**. It decrypts the stored credential (containi
Indicators of compromise
- CVE-2026-70478cve
Original source: https://github.com/advisories/GHSA-qgvm-j2hm-6m38