Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56270

Опубликовано: 24 июн. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter. Remote attackers can send a GET request to harvest sensitive API credentials for Google, Microsoft/Azure, GitHub, and Auth0 integrations. This affects FlowiseAI Cloud and self-hosted instances where the endpoint is exposed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Версия до 3.1.0 (исключая)

EPSS

Процентиль: 39%
0.00475
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
github
5 месяцев назад

Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request

EPSS

Процентиль: 39%
0.00475
Низкий

7.5 High

CVSS3

Дефекты

CWE-306