Executive brief
FlowiseAI Flowise is a visual platform for building AI agents. A server-side request forgery (SSRF) vulnerability in the Evaluations Endpoint allows attackers to manipulate the Host and X-Forwarded-Proto headers, potentially enabling unauthorized access to internal resources and services. This vulnerability affects Flowise versions up to 3.0.2 and has been patched in version 3.1.3.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the axios.post function within packages/server/src/controllers/evaluations/index.ts. The vulnerability stems from insufficient validation of the Host and X-Forwarded-Proto request headers before using them in server-side HTTP requests. An unauthenticated attacker can manipulate these headers to cause the server to make requests to internal or external systems of the attacker's choosing. The attack is network-reachable and does not require authentication. Upgrading to version 3.1.3 or applying patch 700137738bcaebefd4709021f6d6b0abcd7df0ac resolves the issue.
Affected products
- FlowiseAI Flowise up to 3.0.2
Timeline
- 2026-09-13: disclosed: Public disclosure of CVE-2026-90580
- 2026-09-13: patched: Patch 700137738bcaebefd4709021f6d6b0abcd7df0ac released; upgrade to 3.1.3 available