Improper access control in Flowise - CVE-2026-43995

 

Improper access control in Flowise - CVE-2026-43995

Published: April 15, 2026


Vulnerability identifier: #VU126234
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43995
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal network resources and disclose sensitive information.

The vulnerability exists due to improper access control in tool components that directly use node-fetch or axios when processing outbound HTTP requests. A remote user can send a crafted prompt that triggers a vulnerable tool to issue requests to internal or metadata endpoints to access internal network resources and disclose sensitive information.

Only deployments with affected tools enabled are vulnerable.


Affected software

Flowise

How to mitigate CVE-2026-43995

Install security update from vendor's website.

Flowise - update to 3.1.0

External References

Related Security Bulletins