CVE-2026-69257: CWE-918: Server-Side Request Forgery (SSRF) in FlowiseAI Flowise
Flowise versions prior to 3.1.3 contain a Server-Side Request Forgery (SSRF) vulnerability due to improper normalization of IPv4-mapped IPv6 addresses in its HTTP security module. This allows attackers controlling DNS resolution to bypass IP deny lists and make requests to localhost, internal services, or cloud metadata endpoints. The issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
Flowise's HTTP security module (httpSecurity.ts) did not normalize IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) before checking against the deny list. Because ipaddr.js treats these as IPv6 addresses, IPv4 CIDR deny-list checks were skipped. An attacker who controls DNS resolution for hostnames used by HTTP Node, API Chain, Document Loader, MCP tool, or other components using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record with an IPv4-mapped IPv6 address. This causes requests to reach protected internal endpoints such as localhost or cloud metadata services. The vulnerability is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with the ability to control DNS resolution can bypass IP deny lists and cause the application to send requests to internal or sensitive endpoints, potentially exposing internal services or cloud metadata. This can lead to unauthorized information disclosure or further internal network attacks. The CVSS 4.0 score is 7.6 (high severity), reflecting network attack vector, low attack complexity, and partial privileges required.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed by proper normalization of IPv4-mapped IPv6 addresses before deny list checks. No other mitigations are specified or required.
CVE-2026-69257: CWE-918: Server-Side Request Forgery (SSRF) in FlowiseAI Flowise
Description
Flowise versions prior to 3.1.3 contain a Server-Side Request Forgery (SSRF) vulnerability due to improper normalization of IPv4-mapped IPv6 addresses in its HTTP security module. This allows attackers controlling DNS resolution to bypass IP deny lists and make requests to localhost, internal services, or cloud metadata endpoints. The issue is fixed in version 3.1.3.
CVSS v4.0
Score 7.6high
Affected software
FlowiseAI
Flowise
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Flowise's HTTP security module (httpSecurity.ts) did not normalize IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) before checking against the deny list. Because ipaddr.js treats these as IPv6 addresses, IPv4 CIDR deny-list checks were skipped. An attacker who controls DNS resolution for hostnames used by HTTP Node, API Chain, Document Loader, MCP tool, or other components using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record with an IPv4-mapped IPv6 address. This causes requests to reach protected internal endpoints such as localhost or cloud metadata services. The vulnerability is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with the ability to control DNS resolution can bypass IP deny lists and cause the application to send requests to internal or sensitive endpoints, potentially exposing internal services or cloud metadata. This can lead to unauthorized information disclosure or further internal network attacks. The CVSS 4.0 score is 7.6 (high severity), reflecting network attack vector, low attack complexity, and partial privileges required.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed by proper normalization of IPv4-mapped IPv6 addresses before deny list checks. No other mitigations are specified or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.853Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a721340bf8831d5391ad4e6
Added to database: 08/04/2026, 16:28:48 UTC
Last enriched: 08/11/2026, 18:20:28 UTC
Last updated: 09/18/2026, 10:01:33 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.