Description
The attacker provides an intranet address through the base url field configured in the Execute Flow node → Bypass checkDenyList / resolveAndValidate in httpSecurity.ts (not called) → Causes the server to initiate an HTTP request to any internal network address, read cloud metadata, or detect internal network services
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.0.13
- Patched version(s): 3.1.0
References
Related Issues
- Flowise has an MCP Security Bypass that Enables RCE - Vulnerability
- Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox - CVE-2026-41270
- RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests - CVE-2026-39371
- Karakeep SDK has SSRF via metascraper-logo-favicon that bypasses validateUrl protections - Vulnerability
You might also like:
- Tags:
- npm
- flowise-components
Anything's wrong? Let us know Last updated on April 16, 2026


