CVE-2026-90580 | FlowiseAI Flowise up to 3.0.2 Evaluations Endpoint index.ts axios.post Host/X-Forwarded-Proto server-side request forgery (Issue 6687)
A vulnerability was found in FlowiseAI Flowise up to 3.0.2. It has been declared as critical. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-90580. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More