Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2025-71333: Flowise 2.2.4 allows attackers to upload malicious files

CVE-2025-71333
Summary

Flowise through version 2.2.4 has a security flaw that lets attackers upload files to any directory on the server without needing a password. This could allow them to take control of the server or execute malicious code. Update to the latest version of Flowise to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
flowiseai flowise <= 2.2.4
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Original title
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in t...
Original description
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.
nvd CVSS4.0 9.3
Vulnerability type
CWE-73
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026