Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2025-71338: Flowise: Unauthenticated File Writing to Filesystem
CVE-2025-71338
Summary
Flowise's document-store API endpoint allows unauthorized users to write files to the system. This could allow attackers to overwrite critical system files, potentially leading to remote code execution. Update to the latest version of Flowise to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| flowiseai | flowise |
<= 3.1.3 cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* |
Original title
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can...
Original description
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.
nvd CVSS3.1
10.0
nvd CVSS4.0
10.0
Vulnerability type
CWE-73
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026