Executive brief
Flowise is a low-code orchestration framework for building LLM applications. The /api/v1/fetch-links endpoint fails to validate user-supplied URLs before making server-side HTTP requests, allowing an attacker to scan internal networks, enumerate services, and expose sensitive administrative endpoints and credentials. An authenticated attacker can use the Flowise server as a proxy to access internal systems normally protected by firewalls.
Technical details
The vulnerability is a Server-Side Request Forgery (CWE-918) in the fetch-links service, specifically in the xmlScrape and webCrawl functions. When the relativeLinksMethod parameter is set to 'webCrawl' or 'xmlScrape', the application directly calls fetch() with a user-supplied URL without validation or blocklist checks. An authenticated attacker can supply internal network addresses (e.g., http://127.0.0.1:8080/) via the /api/v1/fetch-links endpoint, and the server will make an HTTP request and return parsed link structures from the response. This enables internal service enumeration and discovery of administrative interfaces. The vulnerability is fixed in version 3.0.6; affected version is 3.0.5.
Affected products
- FlowiseAI Flowise 3.0.5
Timeline
- 2025-09-15: disclosed
- 2025-09-15: patched: Fixed in version 3.0.6