CVE-2025-71334

Confirmed PUBLISHED

Flowise - Arbitrary File Access via Missing Chat Flow ID Validation

Vendor: Flowise Product: Flowise

Not yet in CISA KEV

Exploited in the wild Active exploitation observed

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
156
Unique Attacker IPs
8
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 Critical EPSS 1.2%

At a Glance

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints (via streamStorageFile) to read arbitrary files. Arbitrary file write may lead to remote code execution.

CVE Published
Jun 25, 2026
Exploitation Reported
Jul 03, 2026
CVSS
9.3 Critical
EPSS
1.2%
Remote Low complexity No user interaction Unauthenticated

Sensor telemetry available

Affected Versions

Vendor Product Version Status
Flowise
Flowise

0 to < 3.0.6

Affected
Flowise
Flowise

3.0.6

Unaffected

CVE References