Junglewise Threat Intelligence

CVE-2026-51031: FlareSolverr SSRF and local file read in /v1 API

CVE-2026-51031 · Severity: info · CVSS 9.8 · Published 2026-07-20

Executive brief

FlareSolverr, a proxy service used to bypass website protections, contains a security flaw that allows remote attackers to force the server to make unauthorized requests. This can be used to steal sensitive internal data, access private cloud metadata, or read local files from the server's hard drive. Organizations using this tool are at risk of data theft and unauthorized access to their internal network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in FlareSolverr's /v1 API endpoint due to a lack of input validation on the 'url' parameter within the 'request.get' and 'request.post' commands. The application directly passes user-supplied URLs to the 'driver.get()' function of an automated Chrome instance without verifying the protocol, hostname, or IP address. Because the underlying Chrome browser is launched with the '--no-sandbox' flag, attackers can use the 'file://' protocol to perform arbitrary local file reads. Additionally, the flaw can be exploited to access internal network services or cloud provider metadata endpoints (e.g., IMDS). The vulnerability is fixed in version 3.4.7.

Affected products

  • FlareSolverr FlareSolverr < 3.4.7

Timeline

  • 2026-04-13: disclosed: Initial vulnerability report published by researcher
  • 2026-07-20: advisory: CVE-2026-51031 published to NVD

References