LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2025-71333

flowiseai · flowise

Published
CVSS9.8
Severitycritical
WeaknessCWE-73
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71333

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71333.