Flowring Agentflow Arbitrary File Upload Vulnerability Allowing Web Shell Execution

Vulnerability

An arbitrary file upload vulnerability has been identified in Flowring's Agentflow, affecting all versions. This vulnerability allows authenticated remote attackers to upload and execute web shell backdoors, enabling arbitrary code execution on the server.

Impact

Exploitation of this vulnerability leads to arbitrary code execution on the server.

Remediation

Contact the vendor for appropriate mitigation measures.

Added: Feb 10, 2026, 8:34 AM
Updated: Feb 10, 2026, 8:34 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
2.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.