Junglewise Threat Intelligence

CVE-2026-12821: FlowiseAI Flowise path traversal in S3 Document Loader

CVE-2026-12821 · Severity: medium · CVSS 6.3 · Published 2026-06-22

Technologies: FlowiseAI Flowise. Vendors: FlowiseAI.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a security flaw in how it handles files from Amazon S3 storage. An attacker can use specially crafted file names to bypass security boundaries and write files to unauthorized locations on the server. This could lead to data corruption, system instability, or unauthorized access to the underlying server hosting the application.

Technical details

A path traversal vulnerability exists in the S3 Document Loader within FlowiseAI Flowise (up to version 3.1.2). The flaw is located in 'packages/components/nodes/documentloaders/S3/S3.ts', where the application derives local temporary file paths from attacker-controlled S3 object keys without proper sanitization or containment checks. By using object keys containing traversal sequences (e.g., '../'), a remote attacker with the ability to influence S3 bucket contents can escape the intended temporary directory. This allows for arbitrary local file writes and potentially unsafe recursive cleanup operations on the host system. The vendor has reportedly not responded to initial disclosure attempts.

Affected products

  • FlowiseAI Flowise up to 3.1.2

Timeline

  • 2026-06-22: disclosed: Initial public disclosure via VulDB and NVD

References