File Upload Vulnerability in FlowiseAI Affects File Management
CVE-2025-61687
What is CVE-2025-61687?
FlowiseAI, a platform designed to facilitate the creation of customized large language model workflows, contains a file upload vulnerability in version 3.0.7. Authenticated users can exploit this flaw to upload arbitrary files without appropriate validation checks. This oversight means that attackers can store malicious Node.js web shells on the server, leading to potential Remote Code Execution (RCE). The system inadequately validates file extensions, MIME types, and the content of uploaded files, creating an avenue for persistent threats. Although the malicious files do not execute automatically, their presence on the server can be exploited later, especially due to possible administrative errors or additional vulnerabilities. This vulnerability represents a significant threat to the integrity and confidentiality of the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Flowise = 3.0.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
