Executive brief
Flowise, an open-source tool for building LLM applications, is vulnerable to a security flaw in how it handles file paths for data storage. An authenticated user with a valid API token can bypass directory restrictions to write data to unauthorized locations on the server's filesystem. This could allow an attacker to overwrite critical system files, potentially leading to full system takeover or data theft.
Technical details
A path traversal vulnerability (CWE-22) exists in Flowise versions prior to 3.1.0 within the Faiss and SimpleStore (LlamaIndex) vector store components. The root cause is the lack of sanitization for the 'basePath' parameter in the 'upsert' function of Faiss.ts and SimpleStore.ts, which is passed directly to filesystem write operations. An authenticated attacker with 'documentStores:upsert-config' permissions and a valid API token can provide a manipulated path (e.g., using '../' sequences) to write vector store data to arbitrary locations. This can result in overwriting sensitive files, achieving remote code execution by targeting web-accessible directories, or exfiltrating data via network-mounted drives. The issue is resolved in version 3.1.0.
Affected products
- FlowiseAI Flowise < 3.1.0
- FlowiseAI flowise-components < 3.1.0
Timeline
- 2026-04-15: advisory: GitHub Security Advisory published
- 2026-07-08: disclosed: NVD publication date