Impact
The vulnerability exists in Flowise document loader nodes based on Cheerio, Playwright, and Puppeteer. It allows the server to fetch the target resource, bypassing the built‑in SSRF guard. The fetched content is returned as document text, enabling read access to internal services, cloud metadata, or other private network resources. This compromise threatens confidentiality by exposing internal data and can be used to gain further footholds.
Affected Systems
FlowiseAI Flowise versions earlier than 3.1.4 are affected; all releases before this version lack the SSRF protection fix and are vulnerable.
Risk and Exploitability
The CVSS score of 7.6 classifies the flaw as high severity. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is exploitation through crafted payloads sent to document loader nodes – any user or component capable of inserting such URLs can trigger the flaw. Because the flaw bypasses normal SSRF controls, internal network resources can be accessed directly from the server.
OpenCVE Enrichment