Impact
Flowise before version 3.1.4 does not validate the baseURL parameter in chat‑model nodes. As a result, an authenticated user with chatflows:create or chatflows:update permissions can redirect requests to arbitrary hosts. By redirecting requests to cloud metadata services or internal hosts, the attacker can exfiltrate large‑language‑model provider API keys. This breach of confidentiality allows further exploitation of the LLM provider’s services and potentially access to downstream resources that rely on those keys.
Affected Systems
The vulnerability affects all Flowise instances supplied by FlowiseAI, specifically Flowise before release 3.1.4. Any installation of Flowise that remains on a version older than 3.1.4 is at risk. The vendor affected product is "Flowise" from FlowiseAI.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of < 1% indicates a low, though nonzero, likelihood of exploitation. The absence of a KEV listing suggests no documented exploitation yet, but the requirement for authenticated permissions limits the attack surface to users with write access to chatflows. The attack vector is internal: it requires legitimate credentials, but once authorized, it can redirect to arbitrary hosts. The combination of high severity and potential for credential theft warrants immediate attention.
OpenCVE Enrichment