Server-Side Request Forgery (SSRF) in Flowise - #VU146555
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to access internal network resources and disclose sensitive information.
The vulnerability exists due to server-side request forgery (SSRF) in the Cheerio, Playwright, and Puppeteer document loader nodes when fetching user-provided URLs. A remote user can supply a specially crafted URL to access internal network resources and disclose sensitive information.
Response content is returned as document text, and cloud metadata endpoints and other private network resources may be reachable.