cbcvebase.
CVE-2026-41272
published 2026-04-23

CVE-2026-41272: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and…

PriorityP343high7.1CVSS 3.1
AVNACHPRLUINSUCHIHAL
EPSS
0.23%
14.0th percentile
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the allow/deny lists via DNS Rebinding (Time-of-Check Time-of-Use) or by exploiting the default configuration which fails to enforce any deny list. This vulnerability is fixed in 3.1.0.

Affected

2 ranges
VendorProductVersion rangeFixed in
flowiseaiflowise< 3.1.03.1.0
flowiseaiflowise-components< 3.1.03.1.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.