Mehrere Schwachstellen (CVE-2025-71333, CVE-2025-71334, CVE-2025-71336, CVE-2025-71338, CVE-2026-57878, CVE-2026-57879, CVE-2026-57880, CVE-2026-57881) in Flowise

Flowise - Flowise - CRITICAL - CVE-2025-71338. Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint. This flaw allows unauthenticated attackers to exploit unsanitized fileName parameters using ../ sequences, resulting in the ability to write arbitrary files to the filesystem. By targeting critical files such as package.json, attackers can achieve remote code execution when the application restarts, posing significant risks to data integrity and application security.
Quelle: securityvulnerability.io