FlowiseAI Flowise Arbitrary File Upload Vulnerability

Vulnerability

An arbitrary file upload vulnerability has been identified in FlowiseAI Flowise version 2.2.6. The issue resides in the attachments API endpoint, allowing unauthorized users to upload files potentially leading to further exploitation.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious files that the application might execute or serve.

Remediation

A patch for this vulnerability is available. Instructions can be found in the repository's patch file.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.0
exploitability
9.1
remediation
7.7
relevance
0.0
threat
8.2
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.