Path Traversal Vulnerability in Flowise Product by FlowiseAI
CVE-2025-71338
10CRITICAL
What is CVE-2025-71338?
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint. This flaw allows unauthenticated attackers to exploit unsanitized fileName parameters using ../ sequences, resulting in the ability to write arbitrary files to the filesystem. By targeting critical files such as package.json, attackers can achieve remote code execution when the application restarts, posing significant risks to data integrity and application security.
Affected Version(s)
Flowise 0
