Skip to content
FlowiseGHSA-69jq-qr7w-j7qh

FlowiseAI Flowise arbitrary file upload vulnerability

HighCVE-2025-26319 · Published Mar 5, 2025

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
<= 2.2.6No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Severity from
GitHub (reviewed advisory)
Weakness
CWE-434
Also known as
CVE-2025-26319

More Flowise advisories

All Flowise
Advisory
Flowise OS command remote code execution
Critical9.8Aug 14, 2025
FlowiseDB vulnerable to SQL Injection by authenticated users
Medium5.9Apr 7, 2025
Flowise allows arbitrary file write to RCE
Critical10.0Mar 14, 2025
Flowise Pre-auth Arbitrary File Upload
CriticalMar 13, 2025
Flowise OverrideConfig security vulnerability
HighNov 21, 2024
Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting
Medium9.6Sep 25, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.