Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:updat…
High CVSS 8.3
Summary
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-hx55-h48h-7rw9
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-ssrf-and-api-key-exfiltration-via-chat-model-nodes
Timeline
- nvd_ingest NVD