Mehrere Schwachstellen (CVE-2025-71333, CVE-2025-71334, CVE-2025-71336, CVE-2025-71338, CVE-2026-57878, CVE-2026-57879, CVE-2026-57880, CVE-2026-57881) in Flowise
⚠️ CVE-Referenzen:
CVE-2025-71333
CVE-2025-71334
CVE-2025-71336
CVE-2025-71338
CVE-2026-57878
CVE-2026-57879
CVE-2026-57880
CVE-2026-57881
Flowise - Flowise - CRITICAL - CVE-2025-71338.
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint. This flaw allows unauthenticated attackers to exploit unsanitized fileName parameters using ../ sequences, resulting in the ability to write arbitrary files to the filesystem. By targeting critical files such as package.json, attackers can achieve remote code execution when the application restarts, posing significant risks to data integrity and application security.
Quelle: securityvulnerability.io