Arbitrary File Read Vulnerability in Flowise Product by FlowiseAI
CVE-2025-71324
8.7HIGH
What is CVE-2025-71324?
Flowise versions before 3.0.6 are susceptible to an arbitrary file read vulnerability due to improper validation of the chatId parameter in specific API endpoints. This flaw allows attackers to execute path traversal attacks, enabling them to access sensitive files, including the database file, without authentication. Exploiting this vulnerability can lead to unauthorized disclosure of critical information stored in the Flowise database.
Affected Version(s)
Flowise 0 < 3.0.6
Flowise 3.0.6
