Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2025-71333: Flowise 2.2.4 allows attackers to upload malicious files
CVE-2025-71333
Summary
Flowise through version 2.2.4 has a security flaw that lets attackers upload files to any directory on the server without needing a password. This could allow them to take control of the server or execute malicious code. Update to the latest version of Flowise to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| flowiseai | flowise |
<= 2.2.4 cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* |
Original title
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in t...
Original description
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.
nvd CVSS4.0
9.3
Vulnerability type
CWE-73
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026