← Vulnerability feed

Vulnerability record · CVE-2025-26319 · published 4 March 2025

CVE-2025-26319: Flowise unrestricted file upload in attachments API

Flowiseai · Flowise

FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint, classified as CWE-434 unrestricted file upload. Because the endpoint accepts attacker-controlled files, it can lead to remote code execution or full host compromise. The record names only version v2.2.6, so other versions cannot be confirmed as affected or fixed from this data.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no privileges or interaction required, a public exploit reference, and a 99th percentile EPSS score make this an urgent patch target.

What it is

FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint, classified as CWE-434 unrestricted file upload. Because the endpoint accepts attacker-controlled files, it can lead to remote code execution or full host compromise. The record names only version v2.2.6, so other versions cannot be confirmed as affected or fixed from this data.

Impact

An attacker can upload arbitrary files, which in a Node.js application like Flowise can be leveraged to execute code and gain control of the server. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reachable over the network through the /api/v1/attachments HTTP endpoint. The CVSS vector shows no privileges required and no user interaction, so it appears exploitable by an unauthenticated remote attacker, though the description does not explicitly state the authentication requirement.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is 0.55869 (99th percentile) and both references are tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Upgrade Flowise to a version that fixes the /api/v1/attachments upload flaw; the record only names v2.2.6, so confirm the fixed release with the vendor before upgrading.
  • Restrict network access to the Flowise API so /api/v1/attachments is not exposed to untrusted networks.
  • Enforce authentication and authorization on the attachments endpoint if it is not already required.
  • Validate uploaded file type, extension and content, and store uploads outside the web root with no execute permissions.
  • Monitor the vendor advisory and the referenced GitHub repository for patch details.

Detection

  • Review Flowise and reverse-proxy logs for POST requests to /api/v1/attachments, especially from unexpected source IPs.
  • Alert on files written to Flowise upload or attachment directories, particularly executable or script extensions.
  • Monitor for child processes spawned by the Flowise Node.js process, which may indicate uploaded code execution.
  • Check for unexpected outbound connections or web shells following attachment uploads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/dorattias/CVE-2025-26319 ExploitPatchThird Party Advisory
https://github.com/dorattias/CVE-2025-26319 ExploitPatchThird Party Advisory

Track CVE-2025-26319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-71338Flowiseai flowise vulnerabilityFlowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outsid…EPSS 1.2%10.0CVE-2025-59528Flowise CustomMCP node code injection enables remote code executionFlowise 3.0.5 passes user-supplied mcpServerConfig input directly into the JavaScript Function() constructor inside convertToValidJSONString, with no…EPSS 86%analysed9.9CVE-2026-40933Flowiseai flowise os command injection vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…EPSS 1.3%9.9CVE-2025-61913Flowiseai flowise path traversal vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…EPSS 13%9.8CVE-2026-52098Flowiseai flowise code injection vulnerabilityAn issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpointEPSS 1.1%9.8CVE-2026-41267Flowiseai flowise insecure direct object reference vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…EPSS 0.48%9.8CVE-2026-41268Flowiseai flowise improper input validation vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…EPSS 1.2%9.8CVE-2025-58434Flowise forgot-password endpoint leaks reset token, enabling account takeoverFlowise 3.0.5 and earlier returns a valid password reset tempToken and sensitive account details from the forgot-password endpoint without authentica…EPSS 50%analysed

Source: NIST National Vulnerability Database (record CVE-2025-26319), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.