NPM · AUGUST 2026 · CONFIRMED

Flowise OAuth2 Token Refresh Endpoint Vulnerability: Critical Threat

GHSA-QGVM-J2HM-6M38Severity: HIGH

The Flowise package contains a critical vulnerability where the OAuth2 token refresh endpoint is accessible without authentication, allowing attackers to refresh OAuth2 tokens and gain unauthorized access to connected services. Users of affected Flowise versions are at risk.

What happened

The vulnerability in the Flowise package allows unauthenticated access to the OAuth2 token refresh endpoint. This endpoint, when exploited, enables attackers to refresh OAuth2 tokens without proper authentication, leading to unauthorized access to connected services. The vulnerability affects multiple versions of Flowise, as detailed in the provided data. To assess exposure, users should check if their Flowise version is within the affected ranges listed. It is recommended to upgrade to a fixed version or implement the suggested mitigation of removing the refresh endpoint from the whitelist and requiring authentication for this endpoint.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If flowise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats