Executive brief
Flowise is an open-source visual flow builder for AI applications that allows users to create chatflows with various components, including API chain integrations. An unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in the APIChain component by injecting malicious prompts that trick the system into making arbitrary HTTP requests to internal or external services. This could allow attackers to scan internal networks, access cloud metadata endpoints containing credentials, or exfiltrate sensitive data from internal systems.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) flaw in Flowise's APIChain implementation (CWE-918) where user-controlled prompt input is used to generate HTTP requests without proper URL validation. The vulnerable code in postCore.ts extracts URL and data parameters directly from LLM-generated responses based on user-provided API documentation, then passes these to fetch() without checking if the URL matches the intended API endpoint. An unauthenticated attacker can inject malicious prompt templates that override the API documentation with a fake BASE URL pointing to internal services (e.g., http://host.docker.internal:8080), causing the Flowise server to make requests to arbitrary endpoints. The LLM-based API chain trusts its own output implicitly, enabling the attacker to bypass network segmentation and firewall rules by pivoting through the Flowise server. Patches are available in versions 3.1.0 and later (flowise npm package ≤ 3.0.13 affected; flowise-components npm package ≤ 3.0.13 affected).
Affected products
- FlowiseAI Flowise <=3.0.13
Timeline
- 2026-04-16: disclosed
- 2026-04-16: patched: Version 3.1.0 released