---
id: CVE-2026-91938
title: >-
  Flowise versions before 3.1.4 contain a server-side request forgery
  vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that
  bypass SSRF protection
summary: >-
  Flowise versions before 3.1.4 contain a server-side request forgery
  vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that
  bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud
  metadata, inte…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-918
vendor: FlowiseAI
product: Flowise
affected:
  - Flowise < 3.1.4
  - Flowise < 3.1.4
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T20:18:53.960'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91938'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9cvr-5wv9-2gxr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-before-3.1.4-server-side-request-forgery-via-document-loaders
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T18:57:13.614499Z'
epss: 0.00373
epssPercentile: 0.28588
ingestedAt: '2026-09-15T15:39:12.924Z'
---

## Overview

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
