Description
A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.1.3 is able to resolve this issue. The patch is identified as 700137738bcaebefd4709021f6d6b0abcd7df0ac. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The flaw is in the Evaluations Endpoint, where the Host or X‑Forwarded‑Proto header values supplied by a client are trusted. By crafting these headers to any desired value, a remote attacker can cause the server to send an HTTP request to an arbitrary URL, resulting in a server‑side request forgery (CWE‑918). The vulnerability affects FlowiseAI Flowise products up to version 3.0.2, which are no longer supported. The issue is resolved in Flowise version 3.1.3 and later.

Affected Systems

The affected systems are applications running FlowiseAI Flowise up to and including version 3.0.2, which are currently unsupported by the maintainer. Upgrading to Flowise 3.1.3 or later removes the vulnerable code paths.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate risk. Because the EPSS score is < 1%, and the vulnerability is not listed in KEV. A remote attacker can invoke SSRF via the Evaluations Endpoint by setting Host/X‑Forwarded‑Proto headers, potentially allowing access to internal or external services reachable from the server and possibly exfiltrating data. Updating to 3.1.3 removes the insecure header handling, eliminating the SSRF capability.

Generated by OpenCVE AI on September 15, 2026 at 17:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.3 or newer to eliminate the vulnerable code.
  • Restrict the server’s outbound network access operation, limiting the potential impact of SSRF.
  • If the Evaluations Endpoint is not required for your environment, disable it or block incoming requests to that endpoint at the firewall.

Generated by OpenCVE AI on September 15, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.1.3 is able to resolve this issue. The patch is identified as 700137738bcaebefd4709021f6d6b0abcd7df0ac. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
Title FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-918
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:14:47.799Z

Reserved: 2026-09-12T16:41:33.275Z

Link: CVE-2026-90580

cve-icon Vulnrichment

Updated: 2026-09-16T14:14:41.950Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-13T20:16:51.317

Modified: 2026-09-16T15:18:31.623

Link: CVE-2026-90580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)