CVE-2026-56275: Flowise - Server-Side Request Forgery via Execute Flow Base URL
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56275?
CVE-2026-56275 has a risk score of 62, indicating a moderate severity level.
How do I fix CVE-2026-56275?
To resolve CVE-2026-56275, upgrade to Flowise version 3.1.0 or later.
What type of vulnerability is CVE-2026-56275?
CVE-2026-56275 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What impact does CVE-2026-56275 have on systems?
CVE-2026-56275 allows attackers to make unauthorized HTTP requests to internal network addresses.
Who is affected by CVE-2026-56275?
CVE-2026-56275 affects users of Flowise versions prior to 3.1.0.