PT-2026-51508 · Flowise · Flowise
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.0
Description
A server-side request forgery (SSRF) issue exists in the Execute Flow node. This occurs due to missing secureFetch verification in
httpSecurity.ts, allowing attackers to bypass security validation by providing intranet addresses through the base URL field. This can be used to initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services.Recommendations
Update to version 3.1.0 or later.
As a temporary workaround, restrict the use of the base URL field in the Execute Flow node to prevent the use of internal network addresses.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise