Описание
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
EPSS
Процентиль: 28%
0.00348
Низкий
7.1 High
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 7.1
github
3 дня назад
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
EPSS
Процентиль: 28%
0.00348
Низкий
7.1 High
CVSS3
Дефекты
CWE-918