What is CVE-2026-70478?
CVE-2026-70478 in Flowise allows unauthenticated decryption of stored credentials through the 'POST /api/v1/oauth2-credential/refresh/:credentialId' endpoint, which is included in the whitelist and lacks authentication. This affects Flowise versions prior to 3.1.3, and upgrading to the latest version is strongly recommended.
Azərbaycanca: Flowise LLM interfeysində müəyyən edilmiş CVE-2026-70478 zəifliyi autentifikasiya tələb etməyən 'POST /api/v1/oauth2-credential/refresh/:credentialId' endpoint-i vasitəsilə saxlanılan etimadnamələrin icazəsiz deşifrə olunmasına şərait yaradır. Bu, 3.1.3 versiyasından əvvəlki Flowise istifadəçilərinə təsir göstərir və dərhal versiya yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of Flowise are affected by CVE-2026-70478?
This vulnerability affects all versions of Flowise prior to version 3.1.3.
What action is recommended for CVE-2026-70478?
Upgrading to the latest version of Flowise is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.