CVE-2025-71334Patch(flowiseai / flowise)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints (via streamStorageFile) to read arbitrary files. Arbitrary file write may lead to remote code execution.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Peaked 3d ago at 1 mentions (2026-06-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-26: 1Mentions · 2026-07-28: 1Mentions · 2026-07-30: 1Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-07-30: 1Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-28: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-03: 106-2607-2807-3008-03
Signal classification4 categories
Patch
125.0%
Active Exploitation
125.0%
PoC
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-261
Patch1
2026-07-281
Active Exploitation1
2026-07-301
PoC1
2026-08-031
General1
Full discourse4 posts
  • Ryan Dewhurst@ethicalhack3r
    Active Exploitation

    🚨 New KEV added: CVE-2025-71334 KEVIntel has identified active exploitation of Flowise Arbitrary File Access via Missing Chat Flow ID Validation. • CVE published: Jun 25, 2026 • 152 exploitation attempts • 4 attacker IPs • 3 origin countries • Activity still ongoing Not currently listed in CISA KEV. https://kevintel.com/CVE-2025-71334#sensor-telemetry

    Post summary

    The post reports ongoing exploitation of Flowise's arbitrary file access vulnerability (CVE‑2025‑71334) with detailed attempt stats, but provides no PoC, exploit code, or mitigation information.

    12041941
    21.2K followersView on X
  • ET Labs@ET_Labs
    General

    10 new OPEN, 28 new PRO (10 + 18) Lumma Stealer, CVE-2026-57623 (Wordpress W3 Cache RCE), CVE-2025-71334 (Flowise Directory Traversal), and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-08-03-v11248/3407

    Post summary

    The post lists new CVEs with brief references to their exploit type but offers no proof‑of‑concepts, exploit tools, or mitigation details, thus falling under a general vulnerability update.

    03040348
    5.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-71334 — CVSS 9.8/10 ██████████ Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/UJHP3sdB7U

    Post summary

    The tweet alerts that Flowise versions 2.2.8 and earlier suffer a critical arbitrary file access flaw (CVE‑2025‑71334) with a CVSS of 9.8, and announces that a patch is already available.

    10000171
    62 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2025-71334 - critical 🚨 Flowise - Path Traversal > Flowise <= 2.2.8 contains a path traversal vulnerability caused by missing validation... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-71334 @pdnuclei #NucleiTemplates #cve

    Post summary

    A brief tweet announces a CVE‑2025‑71334 path traversal in Flowise <= 2.2.8, highlighting a PoC link (likely a Nuclei template) but no exploit or patch details.

    00000237
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more