← Back to browse · API

CVE-2025-71338

Severity
CRITICAL
CVSS
10.0
EPSS
0.00864
Risk score
40.3
CISA KEV
No
PoC
Yes
Published
2026-06-25
Modified
2026-06-26
First seen
2026-08-07
Aliases
EUVD-2025-210343, GHSA-C3HJ-M5HQ-59XW
Products
FlowiseAI:Flowise 0
Sources
github d352e490909e166980dc15dd|CVE-2025-71338
euvd EUVD-2025-210343

Description

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.

References