Executive brief
Flowise is a visual AI agent builder that makes HTTP requests to external services. The application's security controls meant to prevent malicious requests to internal systems are broken in two ways: they fail by default when not configured, and they can be bypassed via DNS tricks that swap IP addresses between validation and actual connection. An attacker with network-level influence can reach internal systems that should be protected.
Technical details
The vulnerability exists in the secureAxiosRequest and secureFetch wrapper functions in packages/components/src/httpSecurity.ts. Two distinct flaws undermine SSRF protection: (1) Default Insecure—when the HTTP_DENY_LIST environment variable is undefined, the checkDenyList function returns early without blocking any addresses, allowing requests to localhost and other internal addresses; (2) TOCTOU (Time-of-Check Time-of-Use)—the code performs a DNS lookup to validate the destination IP address, but the HTTP client performs a separate DNS lookup when actually connecting. An attacker controlling authoritative DNS can return a safe IP (e.g., 1.1.1.1 with TTL=0) during validation, then return an internal IP (e.g., 127.0.0.1) for the subsequent connection, bypassing the check. Both attacks require the attacker to be on the network or control DNS; the TOCTOU variant has medium complexity. An authenticated attacker can invoke HTTP requests through Flowise nodes to access internal services, potentially reading sensitive data. Patch available in version 3.1.0 for both flowise and flowise-components packages.
Affected products
- FlowiseAI flowise <= 3.0.13
- FlowiseAI flowise-components <= 3.0.13
Timeline
- 2026-04-16: disclosed: Advisory GHSA-2x8m-83vc-6wv4 published
- 2026-04-16: patched: Fixed in versions flowise 3.1.0 and flowise-components 3.1.0