CVE Explorer
CVE-2025-71333
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:npm/flowise","product":"Flowise","vendor":"Flowise","versions":[{"lessThanOrEqual":"2.2.4","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5c68e1afa49a4406caca520ebf90198329951e33e502d0db313f1ea358395907 · sha256:c8a6ded0e400e595… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5c68e1afa49a4406caca520ebf90198329951e33e502d0db313f1ea358395907 · sha256:c8a6ded0e400e595… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-73","description":"External Control of File Name or Path","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5c68e1afa49a4406caca520ebf90198329951e33e502d0db313f1ea358395907 · sha256:c8a6ded0e400e595… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"GitHub Security Advisory (GHSA-h42x-xx2q-6v6g)","tags":["vendor-advisory"],"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-h42x-xx2q-6v6g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5c68e1afa49a4406caca520ebf90198329951e33e502d0db313f1ea358395907 · sha256:c8a6ded0e400e595… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-h42x-xx2q-6v6g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5c68e1afa49a4406caca520ebf90198329951e33e502d0db313f1ea358395907 · sha256:c8a6ded0e400e595… · /containers/adp/0/references/0
{"name":"VulnCheck Advisory: Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/flowise-arbitrary-file-upload-via-unauthenticated-api-v1-attachments-endpoint"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5c68e1afa49a4406caca520ebf90198329951e33e502d0db313f1ea358395907 · sha256:c8a6ded0e400e595… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.