Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.
Published: 2026-08-04
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Flowise, a drag‑and‑drop interface for building large language model flows, contains a flaw in its HTTP security module that fails to normalize IPv4‑mapped IPv6 addresses such as ::ffff:127.0.0.1 before checking them against a deny list. Because the CIDR parsing logic treats these addresses as IPv6 while the deny list contains IPv4 entries, the check is skipped and an attacker can cause the system to resolve a hostname to a private or cloud metadata IP. The weakness is classified as CWE-918 (Server Side Request Forgery) and CWE-1389 (IP Address Normalization Issues). This allows an attacker who can control DNS resolution for a hostname used by the application to force internal requests to localhost, internal services, or cloud metadata endpoints, potentially exposing sensitive data or enabling further compromise.

Affected Systems

The vulnerability affects FlowiseAI's Flowise platform in all releases prior to version 3.1.3. No other product or vendor is listed as impacted.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity vulnerability. EPSS is not available, and the flaw is not in the CISA KEV catalog, suggesting limited but plausible exploitation. The attack vector is inferred to be remote, relying on the attacker’s ability to influence DNS lookups for hostnames that the Flowise application resolves. The vulnerability can be exploited by submitting a crafted hostname that resolves to an IPv4‑mapped IPv6 address pointing to an internal resource, thereby bypassing the intended deny‑list protection.

Generated by OpenCVE AI on August 4, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.3 or later to apply the fix that normalizes IPv4‑mapped IPv6 addresses
  • Restrict DNS resolution performed by the application to a trusted DNS server and validate hostnames before resolution to prevent malicious AAAA records
  • Disable or limit the use of secureAxiosRequest, secureFetch, or checkDenyList for untrusted hostnames to reduce exposure to internal or cloud metadata services

Generated by OpenCVE AI on August 4, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c6xh-wv4j-ppv5 Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Flowiseai
Flowiseai flowise
Vendors & Products Flowiseai
Flowiseai flowise

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.
Title Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Weaknesses CWE-1389
CWE-918
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-04T16:36:51.647Z

Reserved: 2026-08-03T19:54:19.853Z

Link: CVE-2026-69257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-04T17:17:00.840

Modified: 2026-08-04T17:17:00.840

Link: CVE-2026-69257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:30:05Z

Weaknesses
  • CWE-1389

    Incorrect Parsing of Numbers with Different Radices

  • CWE-918

    Server-Side Request Forgery (SSRF)