MEDIUM
CVE-2026-90580
CVSS
6.3
Description
A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.1.3 is able to resolve this issue. The patch is identified as 700137738bcaebefd4709021f6d6b0abcd7df0ac. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.23%
Probability of exploitation in next 30 days
13.7th percentile
References
https://github.com/FlowiseAI/Flowise/
Product
https://github.com/FlowiseAI/Flowise/commit/700137738bcaebefd4709021f6d6b0abcd7df0ac
Patch
https://github.com/FlowiseAI/Flowise/issues/6687
Exploit, Mitigation, Vendor Advisory
https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.3
Patch, Release Notes
https://vuldb.com/cve/CVE-2026-90580
Third Party Advisory, VDB Entry
https://vuldb.com/submit/913327
Third Party Advisory, VDB Entry
https://vuldb.com/vuln/403165
Third Party Advisory, VDB Entry
https://vuldb.com/vuln/403165/cti
Permissions Required
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.