AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-69257

HIGH · CVSS 7.6 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Flowise versions prior to 3.1.3 are vulnerable due to improper normalization of IPv4-mapped IPv6 addresses in its HTTP security module, allowing attackers to bypass deny-list checks. This flaw could enable malicious actors to redirect requests to localhost or internal services, potentially exposing sensitive data or services. Organizations utilizing Flowise for large language model flows should prioritize upgrading to version 3.1.3 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-69257
Severity
HIGH
CVSS
7.6
EPSS
0.25%

Original NVD Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.