Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
Vulnerability Description
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
FlowiseAI Flowise 授权问题漏洞
Vulnerability Description
FlowiseAI Flowise是FlowiseAI公司开源的一款可视化编排语言模型应用流程的工具。 FlowiseAI Flowise 3.1.4及之前版本存在授权问题漏洞,该漏洞源于身份验证中间件中基于前缀的白名单匹配,攻击者可通过向OAuth2凭据刷新端点发送带有尾随凭据标识符的POST请求,绕过所有身份验证和授权检查,触发对任意工作区凭据的未授权OAuth令牌轮换,可能导致依赖的OAuth集成中断。
CVSS Information
N/A
Vulnerability Type
N/A