Vulnerability Description
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flowiseai | Flowise | < 3.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9hrv-gvrv-6gf2ExploitThird Party Advisory
- https://www.vulncheck.com/advisories/flowise-server-side-request-forgery-via-exeThird Party Advisory
FAQ
What is CVE-2026-56275?
CVE-2026-56275 is a vulnerability with a CVSS score of 7.1 (HIGH). Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base ...
How severe is CVE-2026-56275?
CVE-2026-56275 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56275?
Check the references section above for vendor advisories and patch information. Affected products include: Flowiseai Flowise.