CVE-2025-71338: Flowiseai Flowise

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.

Affected products

Published 2026-06-25. Last modified 2026-09-30.