#VU126234 Improper access control in Flowise
Published: April 15, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote user to access internal network resources and disclose sensitive information.
The vulnerability exists due to improper access control in tool components that directly use node-fetch or axios when processing outbound HTTP requests. A remote user can send a crafted prompt that triggers a vulnerable tool to issue requests to internal or metadata endpoints to access internal network resources and disclose sensitive information.
Only deployments with affected tools enabled are vulnerable.