Skip to content

Known CVE

Flowise <= 3.0.13 - Unauthenticated OAuth Configuration Disclosure

Flowise before 3.1.0 contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint, allowing unauthenticated remote attackers to retrieve an organization's complete SSO configuration including OAuth client secrets by providing an organizationId parameter.

CVE-2026-56270

High2026CVSS 7.5CWE-306

cve2026 · flowise · unauth · disclosure · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website