Flowise - Path Traversal
CVE-2025-71324
Verified
Description
Flowise < 3.0.6 contains a path traversal vulnerability caused by improper validation of the chatId parameter in /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints, letting unauthenticated attackers read arbitrary files including sensitive database files.
Severity
High
CVSS Score
7.5
Exploit Probability
2%
Affected Product
Flowise
Published Date
August 4, 2026
Template Author
theamanrawat, pdteam
CVE-2025-71324.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-71324
CWE ID:
cwe-73
Remediation Steps
Update to version 3.0.6 or later.