highCVSS 7.1Vulnerability

GHSA-2x8m-83vc-6wv4

### Summary The core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the allow/deny lists via DNS Rebinding (Time-of-Check Time-of-Use) or by exploiting the default configuration which fails to enforce any deny list. ### Details The flaws exist in `packages/components/src/httpSecurity.ts`. Default Insecure: If process.env.HTTP_DENY_LIST is undefined, checkDenyList returns immediately, allowing all requests (including localhost). DNS Rebinding (TOCTOU): The function performs a DNS lookup (dns.lookup) to validate the IP, and then the HTTP client performs a new lookup to connect. An attacker can serve a valid IP first, then switch to an internal IP (e.g., `127.0.0.1`) for the second lookup. ### PoC Ensure `HTTP_DENY_LIST` is unset (default behavior). Use any node utilizing secureFetch to access `http://127.0.0.1`. Result: Request succeeds. #### Scenario 2: DNS Rebinding Attacker controls domain attacker.com and a custom DNS server. Configure DNS to return `1.1.1.1` (Safe IP) with TTL=0 for the first query. Configure DNS to return `127.0.0.1` (Blocked IP) for subsequent queries. Flowise validates `attacker.com` -> `1.1.1.1` (Allowed). Flowise fetches `attacker.com` -> `127.0.0.1` (Bypass). Run the following for manual verification ```ts // PoC for httpSecurity.ts Bypasses import * as dns from 'dns/promises'; // Mocking the checkDenyList logic from Flowise async function checkDenyList(url: string) { const deniedIPs = ['127.0.0.1', '0.0.0.0']; // Simplified deny list logic if (!process.env.HTTP_DENY_LIST) { console.log(\"⚠️ HTTP_DENY_LIST not set. Returning allowed.\"); return; // Vulnerability 1: Default Insecure } const { hostname } = new URL(url); const { address } = await dns.lookup(hostname); if (deniedIPs.includes(address)) { throw new Error(`IP ${address} is denied`);

Properties

ghsa_id
GHSA-2x8m-83vc-6wv4
summary
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
severity
high
cvss_score
7.1
cve_id
GHSA-2x8m-83vc-6wv4
cvss_vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
is_ghsa_only
true
ghsa_published
2026-04-16T21:51:00Z
source_url
https://github.com/advisories/GHSA-2x8m-83vc-6wv4
ghsa_updated
2026-04-18T00:15:12Z

Related Entities (7)

AFFECTS (2)

[Software]npm/flowise-components
[Software]npm/flowise

HAS_WEAKNESS (2)

[Weakness]Server-Side Request Forgery (SSRF)
[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]npm/flowise
[Software]npm/flowise-components

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2x8m-83vc-6wv4 (CVSS 7.1) — Ninja Signal Threat Intelligence | Ninja Signal