CVE-2025-71338

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
01/07/2026

Description

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* 3.1.3 (including)