What is CVE-2026-67620?
CVE-2026-67620 is an SSRF vulnerability in Flowise up to version 3.1.4, where the DEFAULT_DENY_LIST in httpSecurity.ts omits Oracle Cloud (192.0.0.192) and Alibaba Cloud (100.100.100.200) metadata endpoints. This allows an authenticated attacker to perform server-side requests and potentially access sensitive cloud metadata. Upgrading Flowise to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-67620 Flowise platformasının 3.1.4 versiyasına qədər olan versiyalarında SSRF qorunmasındakı zəiflikdir. httpSecurity.ts faylındakı DEFAULT_DENY_LIST Oracle Cloud (192.0.0.192) və Alibaba Cloud (100.100.100.200) metadata endpoint-lərini bloklamadığı üçün autentifikasiya olunmuş istifadəçi server tərəfli sorğular yaradaraq bu xidmətlərdən həssas məlumatları oxuya bilər. Flowise-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Flowise
FAQ2
Which Flowise versions are affected by CVE-2026-67620?
CVE-2026-67620 affects Flowise up to version 3.1.4.
How to mitigate CVE-2026-67620?
Upgrading Flowise to the latest version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.