Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.
References
| Link | Resource |
|---|---|
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9hrv-gvrv-6gf2 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/flowise-server-side-request-forgery-via-execute-flow-base-url | Third Party Advisory |
Configurations
History
25 Jun 2026, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
| References | () https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9hrv-gvrv-6gf2 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/flowise-server-side-request-forgery-via-execute-flow-base-url - Third Party Advisory | |
| First Time |
Flowiseai flowise
Flowiseai |
23 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 13:16
Updated : 2026-06-25 18:39
NVD link : CVE-2026-56275
Mitre link : CVE-2026-56275
CVE.ORG link : CVE-2026-56275
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-918
Server-Side Request Forgery (SSRF)
