CVE-2026-69257: CWE-918: Server-Side Request Forgery (SSRF) in FlowiseAI Flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
FlowiseAI Flowise before version 3.1.3 has an SSRF vulnerability (CVE-2026-69257) caused by the httpSecurity.ts module not normalizing IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) before checking against the deny list. Because ipaddr.js treats these as IPv6 addresses, IPv4 CIDR deny-list checks are skipped. An attacker who controls DNS resolution for hostnames used by HTTP Node, API Chain, Document Loader, MCP tool, or other components using secureAxiosRequest(), secureFetch(), or checkDenyList() can return AAAA records with IPv4-mapped addresses to bypass restrictions and reach localhost, internal services, or cloud metadata endpoints. This vulnerability has a CVSS 4.0 score of 7.6 (high severity) and is fixed in version 3.1.3.
Potential Impact
An attacker able to control DNS resolution for targeted hostnames can exploit this vulnerability to bypass IP deny lists and cause the application to send requests to internal or sensitive endpoints such as localhost or cloud metadata services. This could lead to unauthorized access to internal resources or sensitive data exposure. The vulnerability requires the attacker to have some control over DNS resolution and partial privileges (low privileges) on the system.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where the issue is fixed by proper normalization of IPv4-mapped IPv6 addresses before deny list checks. No other mitigations are specified. Patch status is confirmed fixed in 3.1.3.
CVE-2026-69257: CWE-918: Server-Side Request Forgery (SSRF) in FlowiseAI Flowise
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.
CVSS v4.0
Score 7.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FlowiseAI Flowise before version 3.1.3 has an SSRF vulnerability (CVE-2026-69257) caused by the httpSecurity.ts module not normalizing IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) before checking against the deny list. Because ipaddr.js treats these as IPv6 addresses, IPv4 CIDR deny-list checks are skipped. An attacker who controls DNS resolution for hostnames used by HTTP Node, API Chain, Document Loader, MCP tool, or other components using secureAxiosRequest(), secureFetch(), or checkDenyList() can return AAAA records with IPv4-mapped addresses to bypass restrictions and reach localhost, internal services, or cloud metadata endpoints. This vulnerability has a CVSS 4.0 score of 7.6 (high severity) and is fixed in version 3.1.3.
Potential Impact
An attacker able to control DNS resolution for targeted hostnames can exploit this vulnerability to bypass IP deny lists and cause the application to send requests to internal or sensitive endpoints such as localhost or cloud metadata services. This could lead to unauthorized access to internal resources or sensitive data exposure. The vulnerability requires the attacker to have some control over DNS resolution and partial privileges (low privileges) on the system.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where the issue is fixed by proper normalization of IPv4-mapped IPv6 addresses before deny list checks. No other mitigations are specified. Patch status is confirmed fixed in 3.1.3.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.853Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a721340bf8831d5391ad4e6
Added to database: 08/04/2026, 16:28:48 UTC
Last enriched: 08/04/2026, 16:42:08 UTC
Last updated: 08/04/2026, 17:17:08 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.