Executive brief
Flowise is an open-source conversational AI platform that allows users to build and deploy chatbots. The file upload API endpoint accepts unauthenticated file uploads but only validates the file type based on the client-supplied MIME type header without checking the actual file content. An attacker can bypass file type restrictions by spoofing the Content-Type header, uploading malicious files (scripts, executables) disguised as permitted file types, leading to potential data theft, malicious file hosting, or remote code execution when those files are later accessed or processed.
Technical details
The vulnerability is a classic MIME type spoofing / arbitrary file upload flaw in the /api/v1/attachments/:chatflowId/:chatId endpoint. The endpoint is whitelisted for unauthenticated access and uses multer for file handling, but validation relies only on the client-supplied file.mimetype field without verifying actual file content (magic bytes) or file extension. An attacker can send a POST request with a malicious executable (e.g., .js, .exe) while setting Content-Type to an allowed type (e.g., application/pdf), and the server will accept and store it via addArrayFilesToStorage in S3, GCS, or local disk. When chained with static file hosting or file retrieval features, this can lead to Stored XSS or RCE. The fix is available in version 3.0.13 and later, which implements proper file type validation using file magic bytes or extension verification.
Affected products
- FlowiseAI Flowise <=3.0.12
Timeline
- 2026-03-05: disclosed
- 2026-03-06: patched: Fixed in version 3.0.13