GHSA-w4hm-rrxg-pxcfMedium· 7.1▾ SunlitDuplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9hrv-gvrv-6gf2. This link is maintained to preserve external references.
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.
flowise < 3.1.0Upgrade to a patched release:
flowise 3.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56275Medium· 7.1Flowise Execute Flow function has an SSRF vulnerability
CVE-2026-69257High· 8.6Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-91935High· 8.3Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts
CVE-2026-91938High· 7.1Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection
CVE-2026-90580Medium· 6.3A vulnerability was found in FlowiseAI Flowise up to 3.0.2
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability