PT-2026-24483 · Flowise · Flowise

Nlgbao1340

·

Published

2026-03-10

·

Updated

2026-04-12

·

CVE-2026-31829

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.0.13
Description Flowise, a drag & drop user interface for building customized large language model flows, contains a Server-Side Request Forgery (SSRF) issue. The application exposes an HTTP Node within AgentFlow and Chatflow that makes server-side HTTP requests using URLs controlled by the user. There are no restrictions on the target hosts, allowing requests to private IP ranges, localhost, or cloud metadata endpoints. This enables an attacker interacting with a publicly exposed chatflow to force the Flowise server to make requests to internal network resources that are otherwise inaccessible from the public internet.
Recommendations Update to version 3.0.13 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-31829
GHSA-FVCW-9W9R-PXC7

Affected Products

Flowise