CVE-2025-59527EPSS p92.0%
CVE-2025-59527CVE-2025-59527
flowiseai / flowise
Description
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulnerability was discovered in the /api/v1/fetch-links endpoint of the Flowise application. This vulnerability allows an attacker to use the Flowise server as a proxy to access internal network web services and explore their link structures. This issue has been patched in version 3.0.6.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 5.00% probability of exploitation · percentile 92.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |