Beveiligingsadvies

CVE-2025-71338

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-25 21:41:07
Laatst bijgewerkt 2026-06-26 12:45:28
Toegewezen door VulnCheck
CVSS-score 10.0
Status PUBLISHED

Beschrijving

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.