Known CVE
Flowise <= 3.0.13 - Unauthenticated OAuth Configuration Disclosure
Flowise before 3.1.0 contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint, allowing unauthenticated remote attackers to retrieve an organization's complete SSO configuration including OAuth client secrets by providing an organizationId parameter.
CVE-2026-56270
High2026CVSS 7.5CWE-306
cve2026 · flowise · unauth · disclosure · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website