PT-2026-34735 · Flowise · Flowise

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41270

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description A Server-Side Request Forgery (SSRF) protection bypass exists in the Custom Function feature. Although the application uses HTTP DENY LIST to protect axios and node-fetch libraries, the built-in Node.js http, https, and net modules are permitted within the NodeVM sandbox without similar protections. This allows authenticated users to circumvent SSRF controls and access internal network resources, such as cloud provider metadata services.
Recommendations Update to version 3.1.0.

Exploit

Fix

Improper Access Control

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41270
GHSA-XHMJ-RG95-44HV

Affected Products

Flowise