Junglewise Threat Intelligence

Flowise arbitrary file read in chatId parameter

Severity: critical · CVSS 9.1 · Published 2025-09-15

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a security flaw that allows unauthenticated users to read sensitive files from the server's local storage. An attacker can exploit this to download the application's database, which contains sensitive information like API keys and configuration data. This could lead to a full takeover of the application and its connected services.

Technical details

An arbitrary file read vulnerability exists in the `chatId` parameter of the `/api/v1/get-upload-file` and `/api/v1/openai-assistants-file/download` endpoints. While the application validates `chatflowId` and `fileName`, it fails to sanitize the `chatId` parameter, which is used in a path-joining operation. A fallback logic in the `streamStorageFile` function allows path traversal sequences to bypass initial directory restrictions, enabling access to files like `database.sqlite`. Although a valid `chatflowId` (UUID) is required, it can be leaked via a verbose error message in the `/api/v1/vector/upsert/` endpoint. The vulnerability is patched in version 3.0.6.

Affected products

  • FlowiseAI Flowise 3.0.5

Timeline

  • 2025-09-13: advisory: GitHub Advisory published
  • 2025-09-15: disclosed

References

Related threats