CVE-2026-41273Disclosure(flowiseai / flowise)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatflow configuration endpoint, an attacker can retrieve internal workflow data, including OAuth credential identifiers, which can then be used to refresh and obtain valid OAuth 2.0 access tokens without authentication. This vulnerability is fixed in 3.1.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-23: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-23: 104-2104-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • JJ (yuasa)@melonattacker
    Disclosure

    Flowiseに報告した脆弱性にCVEが採番されました(CVE-2026-41273) Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6f7g-v4pp-r667

    Post summary

    The advisory announces CVE‑2026‑41273 for Flowise, detailing an unauthenticated OAuth 2.0 access token disclosure stemming from public chatflow usage, with no mention of exploit code, active exploitation, or patch.

    000100536
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41273 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that … https://www.cve.org/CVERecord?id=CVE-2026-41273

    Post summary

    The post announces an authentication‑bypass vulnerability (CVE‑2026‑41273) affecting Flowise versions before 3.1.0, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0001198
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more