


Perceptive Security
SOC/SIEM Consultancy

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secu…
Published:
22 april 2026 om 22:00:00
Alert date:
23 april 2026 om 21:01:44
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies
Flowise, a drag & drop UI for building customized large language model flows, contains Server-Side Request Forgery (SSRF) vulnerabilities in versions prior to 3.1.0. The security flaws exist in core security wrappers (secureAxiosRequest and secureFetch) that are designed to prevent SSRF attacks. Attackers can bypass allow/deny lists through DNS Rebinding attacks (Time-of-Check Time-of-Use) or by exploiting default configurations that fail to enforce deny lists. The vulnerability has been patched in version 3.1.0.
Technical details
Mitigation steps:
Affected products:
Flowise
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41272
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-2x8m-83vc-6wv4
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
