/Vulnerability Library

Flowise - Path Traversal

CVE-2025-71324
Verified

Description

Flowise < 3.0.6 contains a path traversal vulnerability caused by improper validation of the chatId parameter in /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints, letting unauthenticated attackers read arbitrary files including sensitive database files.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

Flowise

Published Date

August 4, 2026

Template Author

theamanrawat, pdteam

CVE-2025-71324.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-71324
CWE ID:
cwe-73

References

https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-99pg-hqvx-r4gfhttps://nvd.nist.gov/vuln/detail/CVE-2025-71324

Remediation Steps

Update to version 3.0.6 or later.