Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-69257 — flowise

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-1389 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses

Summary

Flowise's HTTP security module (httpSecurity.ts) fails to normalize IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1, ::ffff:169.254.169.254) before checking them against the deny list. Due to an ipaddr.js kind mismatch (ipv6 vs ipv4), all IPv4 CIDR deny rules are silently skipped for IPv4-mapped IPv6 addresses. An attacker who controls DNS resolution for a hostname can set a AAAA record to ::ffff:<target_ipv4>, completely bypassing all SSRF protections and accessing internal services, cloud metadata endpoints, and localhost.

CWE

  • CWE-918: Server-Side Request Forgery (SSRF)
  • CWE-1389: Incorrect Parsing of Numbers with Different Radices (IPv4-mapped IPv6 not normalized to IPv4 before deny list check)

Affected Versions

  • All versions up to and including v3.1.1 (latest main branch as of 2026-04-03)
  • This includes versions where CVE-2026-31829 was supposedly patched (v3.0.13+)

Details

Root Cause

The isDeniedIP() function in packages/components/src/httpSecurity.ts checks IP addresses against a deny list using ipaddr.js. The critical flaw is in the kind() comparison:

```typescript

// httpSecurity.ts - isDeniedIP()

export function isDeniedIP(ip: string, denyList: string[]): void {

const parsedIp = ipaddr.parse(ip);

for (const entry of denyList) {

if (entry.includes('/')) {

try {

const [range, _] = entry.split('/')

const parsedRange = ipaddr.parse(range)

// ⚠️ BUG: IPv4-mapped IPv6 has kind='ipv6', IPv4 CIDR has kind='ipv4'

// This condition is FALSE for ::ffff:x.x.x.x vs any IPv4 CIDR entry

if (parsedIp.kind() === parsedRange.kind()) { // <-- BYPASS HERE

if (parsedIp.match(ipaddr.parseCIDR(entry))) {

throw new Error('Access to this host is denied by policy.')

}

}

} catch (error) {

throw new Error(isDeniedIP: ${error})

}

} else if (ip === entry) {

throw new Error('Access to this host is denied by policy.')

}

}

}

```

When the resolved IP is an IPv4-mapped IPv6 address like ::ffff:169.254.169.254:

  • ipaddr.parse('::ffff:169.254.169.254').kind() returns 'ipv6'
  • ipaddr.parse('169.254.169.254').kind() (from deny list entry) returns 'ipv4'
  • 'ipv6' === 'ipv4' is falseCIDR check is completely skipped

The IPv6 deny list entries (::1, fc00::/7, fe80::/10, ff00::/8) do NOT cover the ::ffff:0:0/96 range where IPv4-mapped addresses live, so these addresses bypass ALL deny rules.

Attack Vector

1. Attacker registers a domain (e.g., evil.attacker.com) and sets a AAAA DNS record to ::ffff:169.254.169.254 (AWS metadata) or ::ffff:10.0.0.1 (internal service)

2. Attacker configures a chatflow HTTP Node (or API Chain, Document Loader, etc.) to make a request to http://evil.attacker.com/latest/meta-data/

3. resolveAndValidate() calls dns.lookup('evil.attacker.com', { all: true }) which returns [{ address: '::ffff:169.254.169.254', family: 6 }]

4. isDeniedIP('::ffff:169.254.169.254', denyList) is called — all IPv4 CIDR entries are skipped due to kind mismatch

5. Request is sent to 169.254.169.254 (AWS metadata service) via the IPv4-mapped IPv6 address

Affected Endpoints

All code paths using the SSRF protection functions are vulnerable:

| Function | Usage Count | Affected Components |

|----------|:-----------:|-------------------|

| secureAxiosRequest() | 8+ | HTTP Node (Agentflow), ExecuteFlow, APILoader, FireCrawl, Spider, AzureRerank |

| secureFetch() | 5+ | ApiChain, Custom Function sandbox, Jira tool, MCP tool |

| checkDenyList() | 3+ | MCP Server URL validation, fetch-links service, web scraping |

Proof of Concept

```javascript

// Verify the bypass using ipaddr.js (same library Flowise uses)

const ipaddr = require('ipaddr.js');

const denyList = [

'169.254.169.254/16', // Cloud metadata (covered by 169.254.0.0/16 in Flowise)

'10.0.0.0/8', // RFC1918 (covered by 10.0.0.0/8 in Flowise)

'127.0.0.0/8', // Loopback (covered by 127.0.0.0/8 in Flowise)

'172.16.0.0/12', // RFC1918 (covered by 172.16.0.0/12 in Flowise)

'192.168.0.0/16', // RFC1918 (covered by 192.168.0.0/16 in Flowise)

];

// Normal IPv4 - correctly blocked

const normalIP = ipaddr.parse('169.254.169.254');

console.log('169.254.169.254 kind:', normalIP.kind()); // 'ipv4'

// IPv4-mapped IPv6 - bypasses ALL checks

const mappedIP = ipaddr.parse('::ffff:169.254.169.254');

console.log('::ffff:169.254.169.254 kind:', mappedIP.kind()); // 'ipv6'

console.log('Is IPv4Mapped?:', mappedIP.isIPv4MappedAddress()); // true

console.log('Maps to:', mappedIP.toIPv4Address().toString()); // '169.254.169.254'

// Demonstrate the bypass

for (const entry of denyList) {

co

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. Rated impact: confidentiality high, integrity high, availability low.

CVSS metrics in full

The score comes from this vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Attack requirements: Present — the target has to be in a particular state for the attack to work.
  • Privileges required: Low — an ordinary user account is enough.
  • User interaction: None — nobody has to be tricked into anything.
  • Confidentiality impact: High — total loss, or loss the attacker controls.
  • Integrity impact: High — total loss, or loss the attacker controls.
  • Availability impact: Low — limited, and the attacker does not choose what is affected.

Weakness class

CVE-2026-69257 is classified as CWE-1389: Incorrect Parsing of Numbers with Different Radices. The product parses numeric input assuming base 10 (decimal) values, but it does not account for inputs that use a different base number (radix).

Affected software

CVE-2026-69257 is recorded against 2 packages.

  • flowise
  • unknown

Timeline and source

Published on 4 August 2026 and last revised on 19 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)

Other advisories for this package

flowise has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-1389: Incorrect Parsing of Numbers with Different Radices) in other software:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-1389
Public Exploit ✅ No
Source NVD
Published 2026-08-04
Updated 2026-08-20
Modified 2026-08-19
Fix URL N/A

Affected Packages

Software From version Fixed in
flowise
unknown

Similar Threats

Site Security Check

Is flowise part of your stack?

CVE-2026-69257 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026