A vulnerability labeled as problematic has been found in Flowise up to 3.0.5. This issue affects the function streamStorageFile of the file /api/v1/get-upload-file. Such manipulation of the argument chatId leads to file inclusion. This vulnerability is listed as CVE-2025-71324. The attack may be performed from remote. The affected component should be upgraded.
| Vendor | Product | Versions |
|---|---|---|
| flowi | flowi | 0, 3.0.5 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | open source flowise | cert_advisory | 90% |
Updated vendor and product names, added affected version 3.0.5, changed severity to HIGH, and noted that there is no available exploit.
Initial creation