CVE-2026-91938
7.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Summary
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FlowiseAI | Flowise | 0 < 3.1.4 | affected |
| FlowiseAI | Flowise | 3.1.4 | unaffected |
| FlowiseAI | Flowise | 0 < 3.1.4 | affected |
| FlowiseAI | Flowise | 3.1.4 | unaffected |
Weaknesses
- CWE-918: Server-Side Request Forgery (SSRF)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9cvr-5wv9-2gxr
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-server-side-request-forgery-via-document-loaders
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.