Flowise - Arbitrary File Write to Remote Code Execution via document-store API
Vulnerability Description
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71338
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- pyozzi-toss
References
More from Flowise
View All →Affected Vendor
Flowise
View all reports →