Flowise /api/v1/fetch-links 服务器端请求伪造漏洞 (CVE-2025-59527)

2026-02-25 Flowise PoC No

Description

Flowise 低代码平台的 /api/v1/fetch-links 接口未对用户输入的 URL 参数进行严格验证,允许攻击者构造恶意请求访问内部或外部系统资源,存在服务器端请求伪造(SSRF)漏洞(CVE-2025-59527)。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities