Server-Side Request Forgery Vulnerability in Flowise Product by FlowiseAI
CVE-2026-91938

7.6HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91938?

Prior versions of Flowise (3.1.4 and below) are susceptible to a server-side request forgery (SSRF) vulnerability found in the document loader nodes of Cheerio, Playwright, and Puppeteer. This security flaw allows attackers to craft arbitrary URLs, giving them access to cloud metadata, internal services, and resources on private networks. The response from these requests is returned as document text, which could potentially expose sensitive information if exploited by malicious actors.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kodareef5
.