Impact
The flaw is in the Evaluations Endpoint, where the Host or X‑Forwarded‑Proto header values supplied by a client are trusted. By crafting these headers to any desired value, a remote attacker can cause the server to send an HTTP request to an arbitrary URL, resulting in a server‑side request forgery (CWE‑918). The vulnerability affects FlowiseAI Flowise products up to version 3.0.2, which are no longer supported. The issue is resolved in Flowise version 3.1.3 and later.
Affected Systems
The affected systems are applications running FlowiseAI Flowise up to and including version 3.0.2, which are currently unsupported by the maintainer. Upgrading to Flowise 3.1.3 or later removes the vulnerable code paths.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate risk. Because the EPSS score is < 1%, and the vulnerability is not listed in KEV. A remote attacker can invoke SSRF via the Evaluations Endpoint by setting Host/X‑Forwarded‑Proto headers, potentially allowing access to internal or external services reachable from the server and possibly exfiltrating data. Updating to 3.1.3 removes the insecure header handling, eliminating the SSRF capability.
OpenCVE Enrichment