CVE-2026-31829Disclosure(flowiseai / flowise)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch flowiseai flowise systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflow that performs server-side HTTP requests using user-controlled URLs. By default, there are no restrictions on target hosts, including private/internal IP ranges (RFC 1918), localhost, or cloud metadata endpoints. This enables Server-Side Request Forgery (SSRF), allowing any user interacting with a publicly exposed chatflow to force the Flowise server to make requests to internal network resources that are inaccessible from the public internet. This vulnerability is fixed in 3.0.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-04-12: 1Patch / Workaround · 2026-04-12: 1Technical Details · 2026-03-11: 1Technical Details · 2026-04-12: 103-1003-1104-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
General1
2026-03-111
Disclosure1
2026-04-121
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31829 Server-Side Request Forgery in Flowise Chatflow HTTP Node Before 3.0.13 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31829

    Post summary

    A newly identified Server‑Side Request Forgery vulnerability (CVE‑2026‑31829) affects Flowise Chatflow HTTP Node versions before 3.0.13, as reported on vulmon.com.

    0001028
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Flowise` is affected by a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-31829) in its HTTP Node, potentially allowing internal network access. Investigate network segmentation and outbound request filtering. #Flowise #SSRF #infosec https://www.pulsepatch.io/posts/cve-2026-31829-flowise-ssrf

    Post summary

    Flowise is affected by a Server‑Side Request Forgery (SSRF) vulnerability (CVE‑2026‑31829) that could permit internal network access; recommended mitigations include network segmentation and outbound request filtering.

    0000061
    13 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31829 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflow that … https://www.cve.org/CVERecord?id=CVE-2026-31829

    Post summary

    The post only states the CVE identifier, provides a vendor description of a feature, and links to the CVE record, without any evidence of a PoC, exploit, active attacks, patch, or detailed technical details.

    0000081
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more