Junglewise Threat Intelligence

CVE-2025-71334: FlowiseAI Flowise arbitrary file access and path traversal

CVE-2025-71334 · Severity: critical · CVSS 9.8 · Published 2026-06-25

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, an open-source tool for building LLM applications, is vulnerable to a flaw that allows attackers to read or write files anywhere on the server. By sending specially crafted requests to the application's chat and file management interfaces, an unauthenticated user could steal sensitive data or gain full control over the system. This could lead to a total compromise of the server and any customer data stored within the application.

Technical details

Flowise contains a path traversal vulnerability due to insufficient validation of the 'chatflowId' and 'chatId' parameters in multiple API endpoints. Specifically, the '/api/v1/chatflows' endpoint (via addBase64FilesToStorage) fails to verify that these IDs are valid UUIDs or numbers, allowing an unauthenticated attacker to provide traversal sequences (e.g., '../../') to write arbitrary files. Additionally, the '/api/v1/get-upload-file' and '/api/v1/openai-assistants-file/download' endpoints are susceptible to arbitrary file reads via the streamStorageFile function. Successful exploitation of the file write capability can be leveraged to achieve remote code execution (RCE). The vulnerability is addressed in version 3.0.6.

Affected products

  • FlowiseAI Flowise <= 2.2.8

Timeline

  • 2024-09-14: other: Initial bugfix commit for relative path checks
  • 2025-03-13: patched: Secondary bugfix for arbitrary attachment uploads
  • 2025-09-13: advisory: GitHub Security Advisory published
  • 2026-06-25: disclosed: NVD publication date

References

Related threats