Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3191 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2025-71333EXPLOITEDPATCHED
flowi · flowise

Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint

Description

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.

Affected Products

VendorProductVersions
flowiflowise0

References

  • https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-h42x-xx2q-6v6g(vendor-advisory)
  • https://www.vulncheck.com/advisories/flowise-arbitrary-file-upload-via-unauthenticated-api-v1-attachments-endpoint(third-party-advisory)

Related News (1 articles)

Tier C
VulDB2d ago
CVE-2025-71333 | Flowise up to 2.2.4 /api/v1/attachments chatflowId file inclusion (GHSA-h42x-xx2q-6v6g)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-h42x-xx2q-6v6g
CWECWE-73
PublishedJun 25, 2026
Last enriched2d agov2
Trending Score44
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2025-71327EXP
Flowise - Authentication Bypass via Unprotected Registration Endpoint
Trending: 58
NONECVE-2025-71338EXP
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
Trending: 58
NONECVE-2025-71334EXP
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
Trending: 58
CRITICALCVE-2025-71336EXP
Flowise - Unsandboxed Remote Code Execution via Custom MCP
Trending: 48
HIGHCVE-2025-71324
Flowise - Arbitrary File Read via chatId Parameter
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026
Updated: severity, activelyExploited
Jun 25, 2026
Actively Exploited
Jun 27, 2026
Patch Available
Jun 27, 2026

Version History

v2
Last enriched 2d ago
v2Tier C2d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that no exploit is available.

severityactivelyExploited
via VulDB
v12d ago

Initial creation