High severity7.1NVD Advisory· Published Sep 15, 2026
CVE-2026-91938
CVE-2026-91938
Description
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.