8.7
CVE-2026-91935
- EPSS 0.28%
- Veröffentlicht 15.09.2026 15:17:58
- Zuletzt bearbeitet 20.09.2026 01:16:33
- Erkennungen
Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFlowiseAI
≫
Produkt
Flowise
Default Statusunaffected
Version
0
Version <
3.1.4
Status
affected
Version
3.1.4
Status
unaffected
HerstellerFlowiseAI
≫
Produkt
Flowise
Default Statusunaffected
Version
0
Version <
3.1.4
Status
affected
Version
3.1.4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.2 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 8.3 | 2.8 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-hx55-h48h-7rw9
https://www.vulncheck.com/advisories/flowise-before-3.1.4-ssrf-and-api-key-exfiltration-via-chat-model-nodes