Path Traversal Vulnerability in FlowiseAI Flowise S3 Document Loader
CVE-2026-12821
5.3MEDIUM
What is CVE-2026-12821?
A vulnerability exists within the S3 Document Loader component of FlowiseAI Flowise versions up to 3.1.2. It involves an insecure function located in the S3.ts file, which can be exploited through path traversal techniques. This allows attackers to manipulate file paths, potentially leading to unauthorized access to files within the server. The nature of this vulnerability permits remote execution of the attack. Efforts to notify the vendor regarding this disclosure have not elicited any response.
Affected Version(s)
Flowise 3.1.0
Flowise 3.1.1
Flowise 3.1.2
