PT-2025-9712 · Unknown · Flowiseai Flowise

Dorattias

·

Published

2025-03-04

·

Updated

2026-04-07

·

CVE-2025-26319

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FlowiseAI Flowise version 2.2.6
Description FlowiseAI Flowise version 2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments API endpoint. This allows unauthenticated users to upload malicious files, potentially leading to remote code execution and server takeover. Reports indicate over 20,000 potentially affected instances. The vulnerability is actively exploited.
Recommendations Upgrade to version 2.2.7 or later to address this vulnerability.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-26319
GHSA-69JQ-QR7W-J7QH

Affected Products

Flowiseai Flowise