CVE-2025-71334Flowiseai · Flowise
Vulnerability data via NVD (ingested)
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints (via streamStorageFile) to read arbitrary files. Arbitrary file write may lead to remote code execution.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2025-71334product:"Flowiseai Flowise"http.html:"Flowise"More intel sources (5)
vuln:CVE-2025-71334vulnerabilities.cve_id: CVE-2025-71334CVE-2025-71334CVE-2025-71334"CVE-2025-71334" exploit -site:nvd.nist.gov