CVE-2025-71338: Flowiseai Flowise
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.
Affected products
- Flowiseai Flowise: up to and including 3.1.3
Published 2026-06-25. Last modified 2026-09-30.