{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-91938","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-15T11:06:02.263Z","datePublished":"2026-09-15T15:18:00.389Z","dateUpdated":"2026-09-17T19:28:50.908Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-15T15:18:00.389Z"},"datePublic":"2026-08-31T00:00:00.000Z","title":"Flowise before 3.1.4 Server-Side Request Forgery via document loaders","descriptions":[{"lang":"en","value":"Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Server-Side Request Forgery (SSRF)","cweId":"CWE-918","type":"CWE"}]}],"affected":[{"vendor":"FlowiseAI","product":"Flowise","defaultStatus":"unaffected","packageURL":"pkg:npm/flowise","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"3.1.4"},{"version":"3.1.4","status":"unaffected","versionType":"semver"}]},{"vendor":"FlowiseAI","product":"Flowise","defaultStatus":"unaffected","packageURL":"pkg:npm/flowise-components","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"3.1.4"},{"version":"3.1.4","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1.4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1.4"}]}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":7.6,"baseSeverity":"HIGH"}}],"references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9cvr-5wv9-2gxr","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-9cvr-5wv9-2gxr)"},{"name":"VulnCheck Advisory: Flowise before 3.1.4 Server-Side Request Forgery via document loaders","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/flowise-before-3.1.4-server-side-request-forgery-via-document-loaders"}],"credits":[{"lang":"en","value":"kodareef5","type":"reporter"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T18:57:13.614499Z","id":"CVE-2026-91938","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T19:28:50.908Z"}}]}}