CVE-2025-71333

🔴 Łataj teraz

Luka w Flowise umożliwia nieautoryzowane przesyłanie plików, co może prowadzić do zdalnego wykonania kodu.

CVSS
9.8
EPSS
0.6%
Exploit
poc
Vendor
flowiseai
Opis źródłowy (NVD)

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.

exploit path-traversal rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-06-25 22:16:59 UTC
Ostatnia modyfikacja (NVD)2026-07-01 15:10:52 UTC
Referencje