Vulnerability record · CVE-2025-26319 · published 4 March 2025
CVE-2025-26319: Flowise unrestricted file upload in attachments API
Flowiseai · Flowise
FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint, classified as CWE-434 unrestricted file upload. Because the endpoint accepts attacker-controlled files, it can lead to remote code execution or full host compromise. The record names only version v2.2.6, so other versions cannot be confirmed as affected or fixed from this data.
Description
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or interaction required, a public exploit reference, and a 99th percentile EPSS score make this an urgent patch target.
What it is
FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint, classified as CWE-434 unrestricted file upload. Because the endpoint accepts attacker-controlled files, it can lead to remote code execution or full host compromise. The record names only version v2.2.6, so other versions cannot be confirmed as affected or fixed from this data.
Impact
An attacker can upload arbitrary files, which in a Node.js application like Flowise can be leveraged to execute code and gain control of the server. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The flaw is reachable over the network through the /api/v1/attachments HTTP endpoint. The CVSS vector shows no privileges required and no user interaction, so it appears exploitable by an unauthenticated remote attacker, though the description does not explicitly state the authentication requirement.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is 0.55869 (99th percentile) and both references are tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Upgrade Flowise to a version that fixes the /api/v1/attachments upload flaw; the record only names v2.2.6, so confirm the fixed release with the vendor before upgrading.
- Restrict network access to the Flowise API so /api/v1/attachments is not exposed to untrusted networks.
- Enforce authentication and authorization on the attachments endpoint if it is not already required.
- Validate uploaded file type, extension and content, and store uploads outside the web root with no execute permissions.
- Monitor the vendor advisory and the referenced GitHub repository for patch details.
Detection
- Review Flowise and reverse-proxy logs for POST requests to /api/v1/attachments, especially from unexpected source IPs.
- Alert on files written to Flowise upload or attachment directories, particularly executable or script extensions.
- Monitor for child processes spawned by the Flowise Node.js process, which may indicate uploaded code execution.
- Check for unexpected outbound connections or web shells following attachment uploads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/dorattias/CVE-2025-26319 | ExploitPatchThird Party Advisory |
| https://github.com/dorattias/CVE-2025-26319 | ExploitPatchThird Party Advisory |
Track CVE-2025-26319 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-26319), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.