PT-2026-34734 · Flowise · Flowise
Published
2026-04-16
·
Updated
2026-04-23
·
CVE-2026-41269
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.0
Description
The Chatflow configuration file upload settings can be modified to allow the 'application/javascript' MIME type. This allows the upload of .js files, bypassing frontend restrictions. An attacker can use this to persistently store malicious Node.js web shells on the server, which may lead to Remote Code Execution (RCE), a process where an attacker can execute arbitrary commands on the target machine.
Recommendations
Update to version 3.1.0.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise