Description
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Exfiltration of LLM provider API keys
Action: Patch
AI Analysis

Impact

Flowise before version 3.1.4 does not validate the baseURL parameter in chat‑model nodes. As a result, an authenticated user with chatflows:create or chatflows:update permissions can redirect requests to arbitrary hosts. By redirecting requests to cloud metadata services or internal hosts, the attacker can exfiltrate large‑language‑model provider API keys. This breach of confidentiality allows further exploitation of the LLM provider’s services and potentially access to downstream resources that rely on those keys.

Affected Systems

The vulnerability affects all Flowise instances supplied by FlowiseAI, specifically Flowise before release 3.1.4. Any installation of Flowise that remains on a version older than 3.1.4 is at risk. The vendor affected product is "Flowise" from FlowiseAI.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of < 1% indicates a low, though nonzero, likelihood of exploitation. The absence of a KEV listing suggests no documented exploitation yet, but the requirement for authenticated permissions limits the attack surface to users with write access to chatflows. The attack vector is internal: it requires legitimate credentials, but once authorized, it can redirect to arbitrary hosts. The combination of high severity and potential for credential theft warrants immediate attention.

Generated by OpenCVE AI on September 20, 2026 at 16:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 or later.
  • Limit chatflows:create and chatflows:update permissions to only trusted or privileged accounts.
  • Implement firewall rules that block outbound traffic from the Flowise environment to cloud metadata services or untrusted internal hosts.

Generated by OpenCVE AI on September 20, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
Title Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-918
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:29.975Z

Reserved: 2026-09-15T11:06:02.263Z

Link: CVE-2026-91935

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:32.908Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:44.867

Modified: 2026-09-20T01:16:33.733

Link: CVE-2026-91935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)