Flowise - Path Traversal
CVE-2025-71334
Verified
Description
Flowise <= 2.2.8 contains a path traversal vulnerability caused by missing validation of chatflowId and chatId parameters in file handling, letting unauthenticated attackers read and write arbitrary files, exploit requires no authentication.
Severity
Critical
CVSS Score
9.8
Exploit Probability
4%
Affected Product
flowise
Published Date
July 29, 2026
Template Author
theamanrawat
CVE-2025-71334.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-71334
CWE ID:
cwe-73
Remediation Steps
Update to version 3.0.6 or later.