PT-2026-56430 · Flowise · Flowise
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.0
Description
Path traversal occurs in the Faiss and SimpleStore vector store implementations. The issue arises when the system accepts unsanitized
basePath parameters from authenticated users. Attackers possessing valid API tokens can write vector store data to arbitrary locations on the filesystem, which may lead to data exfiltration or code execution.Recommendations
Update to version 3.1.0 or later.
Restrict the use of the
basePath parameter in Faiss and SimpleStore implementations until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise