CVE-2025-71333
🔴 Łataj teraz
Luka w Flowise umożliwia nieautoryzowane przesyłanie plików, co może prowadzić do zdalnego wykonania kodu.
CVSS
9.8
EPSS
0.6%
Exploit
poc
Vendor
flowiseai
Opis źródłowy (NVD)
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.
exploit path-traversal rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-06-25 22:16:59 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-01 15:10:52 UTC |
Referencje
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-h42x-xx2q-6v6g (disclosure@vulncheck.com) [Vendor Advisory, Exploit]
- https://www.vulncheck.com/advisories/flowise-arbitrary-file-upload-via-unauthenticated-api-v1-attachments-endpoint (disclosure@vulncheck.com) [Third Party Advisory]