SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-91938

HIGH · CVSS 7.1 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Versions of Flowise prior to 3.1.4 are susceptible to a server-side request forgery (SSRF) vulnerability that allows attackers to exploit document loader nodes in Cheerio, Playwright, and Puppeteer. This flaw enables unauthorized access to cloud metadata and internal services, potentially exposing sensitive information from private network resources. Organizations using affected versions should prioritize patching to mitigate the risk of data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91938
Severity
HIGH
CVSS
7.1
EPSS
0.35%

Original NVD Description

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.