Path Traversal Vulnerability in FlowiseAI Flowise S3 Document Loader
CVE-2026-12821

5.3MEDIUM

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
21 June 2026

What is CVE-2026-12821?

A vulnerability exists within the S3 Document Loader component of FlowiseAI Flowise versions up to 3.1.2. It involves an insecure function located in the S3.ts file, which can be exploited through path traversal techniques. This allows attackers to manipulate file paths, potentially leading to unauthorized access to files within the server. The nature of this vulnerability permits remote execution of the attack. Efforts to notify the vendor regarding this disclosure have not elicited any response.

Affected Version(s)

Flowise 3.1.0

Flowise 3.1.1

Flowise 3.1.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ST4R (VulDB User)
VulDB CNA Team
.