PT-2026-69209 · Flowise · Flowise

·

CVE-2026-67620

·

Published

2026-08-08

·

Updated

2026-08-08

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.5
Description A server-side request forgery (SSRF) issue exists in the SSRF guard within httpSecurity.ts because the DEFAULT DENY LIST fails to include the Oracle Cloud Infrastructure metadata endpoint (192.0.0.192) and the Alibaba Cloud metadata endpoint (100.100.100.200). Authenticated attackers can exploit this by sending requests to the 'fetch-links' API endpoint using a crafted URL parameter, bypassing deny-list validation through methods such as redirects. This allows the server to issue arbitrary GET requests to cloud instance metadata services, potentially exposing instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments. Unauthenticated access is possible if URL-fetching nodes are present in public chatflows.
Recommendations Update to a version newer than 3.1.4. Restrict access to the 'fetch-links' API endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67620

Affected Products

Flowise