CVE-2026-41273: Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatflow configuration endpoint, an attacker can retrieve internal workflow data, including OAuth credential identifiers, which can then be used to refresh and obtain valid OAuth 2.0 access tokens without authentication. This vulnerability is fixed in 3.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41273?
CVE-2026-41273 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive OAuth 2.0 tokens.
How do I fix CVE-2026-41273?
To fix CVE-2026-41273, upgrade Flowise to version 3.1.0 or later.
What can attackers do with CVE-2026-41273?
Attackers can exploit CVE-2026-41273 to disclose OAuth 2.0 access tokens, allowing unauthorized access to protected resources.
Which versions of Flowise are affected by CVE-2026-41273?
All versions of Flowise prior to 3.1.0 are affected by CVE-2026-41273.
Is authentication required to exploit CVE-2026-41273?
No, CVE-2026-41273 can be exploited by unauthenticated attackers.