CVE-2025-59527

🟡 Monitoruj

W podatnej wersji Flowise występuje SSRF, co pozwala atakującemu na dostęp do usług wewnętrznych.

CVSS
7.5
EPSS
5.0%
Exploit
poc
Vendor
flowiseai
Opis źródłowy (NVD)

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulnerability was discovered in the /api/v1/fetch-links endpoint of the Flowise application. This vulnerability allows an attacker to use the Flowise server as a proxy to access internal network web services and explore their link structures. This issue has been patched in version 3.0.6.

exploit ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)5.0%
Opublikowano (NVD)2025-09-22 20:15:39 UTC
Ostatnia modyfikacja (NVD)2026-09-30 17:10:00 UTC
Referencje