Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6pcv-j4jx-m4vx | Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request |
Wed, 24 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter. Remote attackers can send a GET request to harvest sensitive API credentials for Google, Microsoft/Azure, GitHub, and Auth0 integrations. This affects FlowiseAI Cloud and self-hosted instances where the endpoint is exposed. | |
| Title | Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-24T12:46:16.027Z
Reserved: 2026-06-20T01:47:54.000Z
Link: CVE-2026-56270
Updated: 2026-06-24T12:45:04.479Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T16:04:13Z
Github GHSA