Server-Side Request Forgery (SSRF) in Flowise - #VU146555

 

Server-Side Request Forgery (SSRF) in Flowise - #VU146555

Published: September 1, 2026


Vulnerability identifier: #VU146555
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal network resources and disclose sensitive information.

The vulnerability exists due to server-side request forgery (SSRF) in the Cheerio, Playwright, and Puppeteer document loader nodes when fetching user-provided URLs. A remote user can supply a specially crafted URL to access internal network resources and disclose sensitive information.

Response content is returned as document text, and cloud metadata endpoints and other private network resources may be reachable.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins