CVE-2026-90580
Last modified
CVE-2026-90580 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint.
Description
A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.1.3 is able to resolve this issue. The patch is identified as 700137738bcaebefd4709021f6d6b0abcd7df0ac. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FlowiseAI | Flowise | 3.0.0; 3.0.1; 3.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90580?
How severe is CVE-2026-90580?
How do I fix CVE-2026-90580?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90575A weakness has been identified in PHPGurukul Small CRM 4.0. …3.7
- CVE-2026-90576A security vulnerability has been detected in GPAC up to f12…3.3
- CVE-2026-90577A vulnerability was detected in GPAC up to f1219cde. Affecte…5.3
- CVE-2026-90578A flaw has been found in GPAC up to f1219cde. Affected by th…5.3
- CVE-2026-90579A vulnerability has been found in cheshire-cat-ai Cheshire C…7.3
- CVE-2026-9058For untrusted certificates that contain the "Authority Infor…9.3
- CVE-2026-90581A vulnerability was determined in cym1102 nginxWebUI up to 4…6.3
- CVE-2026-90582A vulnerability was identified in evanchiu serverless-todo 1…5.3
- CVE-2026-90583A security flaw has been discovered in kagisearch smallweb u…4.3
- CVE-2026-9059NextGEN Gallery version prior to 4.2.1 are vulnerable to aut…9.3
- CVE-2026-9060The Store Locator WordPress plugin before 1.6.6 does not san…3.5
- CVE-2026-9061The Store Locator WordPress plugin before 1.6.9 does not san…3.5
Are you affected by CVE-2026-90580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
