FlowiseGHSA-69jq-qr7w-j7qh
FlowiseAI Flowise arbitrary file upload vulnerability
HighCVE-2025-26319 · Published Mar 5, 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| flowise npm | <= 2.2.6 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-434
- Also known as
- CVE-2025-26319
More Flowise advisories
All Flowise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 142025 | Flowise OS command remote code execution | Critical9.8 | No fix yet |
| Apr 72025 | FlowiseDB vulnerable to SQL Injection by authenticated users | Medium5.9 | No fix yet |
| Mar 142025 | Flowise allows arbitrary file write to RCE | Critical10.0 | No fix yet |
| Mar 132025 | Flowise Pre-auth Arbitrary File Upload | Critical | No fix yet |
| Nov 212024 | Flowise OverrideConfig security vulnerability | High | 2.1.4 |
| Sep 252024 | Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting | Medium9.6 | 2.1.1 |