Vulnerabilities/

NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

Severity:
Medium

Description

NocoBase’s workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost.

Recommendation

Update the @nocobase/plugin-workflow-request package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nocobase/plugin-workflow-request
Anything's wrong? Let us know Last updated on May 14, 2026