Server-Side Request Forgery Vulnerability in Flowise Product by FlowiseAI
CVE-2026-91938
7.6HIGH
What is CVE-2026-91938?
Prior versions of Flowise (3.1.4 and below) are susceptible to a server-side request forgery (SSRF) vulnerability found in the document loader nodes of Cheerio, Playwright, and Puppeteer. This security flaw allows attackers to craft arbitrary URLs, giving them access to cloud metadata, internal services, and resources on private networks. The response from these requests is returned as document text, which could potentially expose sensitive information if exploited by malicious actors.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 0 < 3.1.4
Flowise 3.1.4
