Executive brief
Flowise is a visual AI application builder that allows users to design workflows with LLM agents. A flaw in its SSRF protection allows authenticated users to bypass the metadata endpoint deny-list and force the server to retrieve cloud instance credentials from Oracle Cloud Infrastructure or Alibaba Cloud metadata services. An attacker with authentication credentials could steal instance identity data and role credentials, potentially compromising cloud infrastructure.
Technical details
Flowise implements an SSRF guard in httpSecurity.ts with a DEFAULT_DENY_LIST to block requests to cloud metadata services. However, the deny-list is incomplete: it covers the 169.254.0.0/16 link-local range used by AWS, GCP, Azure, and DigitalOcean, but omits the Oracle Cloud metadata endpoint 192.0.0.192 and the Alibaba Cloud endpoint 100.100.100.200. An authenticated attacker can send crafted requests to the fetch-links API endpoint with a URL parameter pointing to these unblocked metadata addresses, bypassing deny-list validation and reaching instance metadata services. The vulnerability also permits unauthenticated exploitation if URL-fetching nodes exist in public chatflows. Successful exploitation allows retrieval of instance identity data and role credentials. The Flowise project has been sunset and will not issue patches; operators must implement manual mitigations.
Affected products
- Flowise Flowise through 3.1.4
Timeline
- 2026-08-08: disclosed
- 2026-07-10: other: Vulnerability discovered
- 2026-07-15: other: Reported to VulnCheck CVD
- 2026-07-29: other: Flowise project sunset announcement