High severity7.1NVD Advisory· Published Jun 23, 2026· Updated Jun 25, 2026
CVE-2026-56275
CVE-2026-56275
Description
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity.ts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-9hrv-gvrv-6gf2nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/flowise-server-side-request-forgery-via-execute-flow-base-urlnvdThird Party Advisory
News mentions
1- Flowise: Nine Vulnerabilities Including RCE and SSRF Disclosed in BatchVypr Intelligence · Jun 23, 2026