CVE-2025-71338
EUVD-2025-21034325.06.2026, 22:16
Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flowiseai | flowise | 𝑥 ≤ 3.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References