PT-2026-52612 · Flowise · Flowise
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 2.2.5
Description
An unauthenticated arbitrary file upload issue exists when
storageType is set to local. This allows attackers to use path traversal—a technique used to access files and directories outside the intended folder—via the chatId and chatflowId parameters in the '/api/v1/attachments' endpoint. This can lead to the upload of malicious files to arbitrary directories, potentially resulting in remote code execution and full server compromise.Recommendations
Update Flowise to version 2.2.5 or later.
As a temporary mitigation, avoid setting
storageType to local or restrict access to the '/api/v1/attachments' endpoint.Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowise