PT-2026-51508 · Flowise · Flowise

·

CVE-2026-56275

·

Published

2026-04-16

·

Updated

2026-06-25

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description A server-side request forgery (SSRF) issue exists in the Execute Flow node. This occurs due to missing secureFetch verification in httpSecurity.ts, allowing attackers to bypass security validation by providing intranet addresses through the base URL field. This can be used to initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services.
Recommendations Update to version 3.1.0 or later. As a temporary workaround, restrict the use of the base URL field in the Execute Flow node to prevent the use of internal network addresses.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56275
GHSA-9HRV-GVRV-6GF2

Affected Products

Flowise