Junglewise Threat Intelligence

CVE-2025-71333: Flowise unauthenticated arbitrary file upload in attachments endpoint

CVE-2025-71333 · Severity: medium · CVSS 4 · Published 2026-06-25

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise, an open-source tool for building LLM-based applications, contains a security flaw that allows unauthorized users to upload files to the server. By exploiting this, an attacker could overwrite critical system files, steal API keys, or take complete control of the server. This poses a significant risk to data confidentiality and the overall availability of the service.

Technical details

An unauthenticated arbitrary file upload vulnerability exists in Flowise versions up to and including 2.2.4. The issue resides in the `/api/v1/attachments` endpoint, which is included in a whitelist of routes that bypass authentication. When the `storageType` is set to 'local', the application fails to validate the `chatId` and `chatflowId` parameters. An attacker can use path traversal sequences (e.g., `../`) within these parameters to escape the intended storage directory and write arbitrary files to any location on the filesystem accessible by the application process. This can lead to remote code execution (RCE) by overwriting configuration files or application scripts. As of the advisory date, no patched version is specified.

Affected products

  • FlowiseAI Flowise <= 2.2.4

Timeline

  • 2025-03-13: advisory: GitHub Security Advisory published
  • 2026-06-25: disclosed: NVD publication date

References

Related threats