Server-Side Request Forgery (SSRF) in Flowise - #VU129628
Published: November 21, 2024 / Updated: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to improper access control in the overrideConfig option when processing user-supplied configuration through the Prediction API or web embed integration. A remote attacker can supply crafted overrideConfig values to perform server-side request forgery.
The issue is self-targeted and does not persist to other users.