What is CVE-2026-69250?
The OAuth2 token refresh endpoint in Flowise LLM interface operates without authentication, allowing attackers to perform server-side HTTP requests. This vulnerability affects Flowise versions prior to 3.1.3. Users should upgrade to version 3.1.3 to mitigate the issue.
Azərbaycanca: Flowise LLM interfeysində OAuth2 token yeniləmə endpoint-i autentifikasiyasız işləyir. Bu zəiflik vasitəsilə uzaqdan hücum edən şəxs server tərəfində HTTP sorğuları həyata keçirə bilər. Flowise istifadəçiləri 3.1.3 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: Flowise
FAQ2
What threat does the unauthenticated OAuth2 token refresh endpoint in Flowise LLM interface pose?
This vulnerability (CVE-2026-69250) allows remote attackers to perform server-side HTTP requests.
What should I do to remediate CVE-2026-69250?
Flowise users should upgrade to version 3.1.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.