- Description
- Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints (via streamStorageFile) to read arbitrary files. Arbitrary file write may lead to remote code execution.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- flowise
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- disclosure@vulncheck.com
- CWE-73
- Hype score
- Not currently trending
10 new OPEN, 28 new PRO (10 + 18) Lumma Stealer, CVE-2026-57623 (Wordpress W3 Cache RCE), CVE-2025-71334 (Flowise Directory Traversal), and more. https://t.co/h5vzXC8HnL
@ET_Labs
3 Aug 2026
288 Impressions
3 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ CVE-2025-71334 - critical ๐จ Flowise - Path Traversal > Flowise <= 2.2.8 contains a path traversal vulnerability caused by missing validation... ๐พ https://t.co/hXNyESgSxH @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
30 Jul 2026
183 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ New KEV added: CVE-2025-71334 KEVIntel has identified active exploitation of Flowise Arbitrary File Access via Missing Chat Flow ID Validation. โข CVE published: Jun 25, 2026 โข 152 exploitation attempts โข 4 attacker IPs โข 3 origin countries โข Activity still ongoi
@ethicalhack3r
28 Jul 2026
833 Impressions
2 Retweets
4 Likes
1 Bookmark
1 Reply
0 Quotes
๐จ CVE-2025-71334 โ CVSS 9.8/10 โโโโโโโโโโ Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/UJHP3sdB7U
@OrizonCyber
26 Jun 2026
117 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5DE0B76C-5FFA-40E2-87E1-5C520E387AF0",
"versionEndExcluding": "3.0.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]