Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
- Severity:
- High
Description
Description: Flowise exposes an HTTP Node in AgentFlow and Chatflow that performs server-side HTTP requests using user-controlled URLs. By default, there are no restrictions on target hosts, including private/internal IP ranges (RFC 1918), localhost, or cloud metadata endpoints.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.0.12
- Patched version(s): 3.0.13
References
Related Issues
- pdfmake is vulnerable to server-side request forgery (SSRF) - CVE-2026-26801
- Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads - CVE-2026-27567
- HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis - CVE-2026-46391
- LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection - CVE-2026-25528
You might also like:
- Tags:
- npm
- flowise-components
Anything's wrong? Let us know Last updated on April 10, 2026


