CVE-2026-91938

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.

Scoring

Severity
HIGH
CVSS base score
7.6
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS probability
0.35%
CWE
CWE-918
Published
2026-09-15
Last modified
2026-09-17

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs