This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
STACKFLAG
stackflag.bsky.social
did:plc:zhe53h7ajlloep2oso5pqxzj
CVE-2026-70478 - flowise
Flowise's OAuth token refresh endpoint can be accessed without a password, allowing an attacker to steal access tokens for connected services like Google or Microsoft. This is…
Too many irrelevant or confusing CVEs? Use stackflag.com
#flowise #flowiseai #npm #CVE #infosec
https://stackflag.com/vulnerabilities/cve-2026-70478-flowise?utm_source=bluesky&utm_medium=social&utm_campaign=cve_poster&utm_content=cve-2026-70478
2026-08-04T21:14:04.366Z