CVE-2025-71338Patch(flowiseai / flowise)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-06-25); latest day: 2
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-27: 1Mentions · 2026-07-03: 1Mentions · 2026-08-05: 2Mentions · 2026-08-31: 2PoC Mentioned / Linked · 2026-08-05: 1PoC Mentioned / Linked · 2026-08-31: 1Exploit Tool / Code · 2026-08-05: 1Exploit Tool / Code · 2026-08-31: 1Patch / Workaround · 2026-06-25: 2Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-27: 1Technical Details · 2026-07-03: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-31: 106-2506-2707-0308-0508-31
Signal classification4 categories
Patch
337.5%
Disclosure
225.0%
Exploit
225.0%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-252
Patch2
2026-06-271
Patch1
2026-07-031
Disclosure1
2026-08-052
Disclosure1Exploit1
2026-08-312
Exploit1General1
Full discourse8 posts
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-nWj2Sy0 ( CVE-2026-42826 ) EGE-GH-FLy7Zaa ( CVE-2025-71338 ) EGE-GH-lPbsTBU ( CVE-2026-52887 ) EGE-GH-KAmy9Px ( CVE-2026-15409 ) EGE-GH-3TfhoOr ( CVE-2026-69083 ) ..🧵👇

    Post summary

    The tweet announces the disclosure of several critical CVEs (e.g., CVE‑2026‑42826, CVE‑2025‑71338) without providing PoC, exploit details, or mitigation information.

    1000163
    29 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [CVE] CVE-2025-71338 [CRITICAL/PoC] #Flowise - Arbitrary File Write to Remote Code Execution via document-store API ⚠️ Recorded Exploit Available 🔗 https://exploitgrid.net/cve/CVE-2025-71338

    Post summary

    CVE-2025-71338 exposes an arbitrary file write that leads to RCE, and a recorded exploit and PoC are publicly available via the provided link.

    1000040
    38 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2025-71338 - EXPLOIT CVE-2025-71389 - EXPLOIT CVE-2026-0092 - EXPLOIT CVE-2026-0848 - EXPLOIT CVE-2026-12485 - EXPLOIT ..🧵👇

    Post summary

    The digest lists several CVEs labeled as "EXPLOIT" without offering any additional information, serving as a general threat highlight.

    1000063
    38 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-FLy7Zaa [CRITICAL/PoC] Linked: CVE-2025-71338 flowise-arbitrary-file-read-getFileFromStorage 🔗 https://exploitgrid.net/exploits/67f918ec-6950-46f5-9e6c-4f933839c32f

    Post summary

    A public exploit code demonstrating an arbitrary file read vulnerability in Flowise (CVE‑2025‑71338) has been shared, complete with a link to the exploit grid page. No active exploitation or patch information is reported.

    1000052
    29 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🧨 AI and Low-Code Platforms: A Growing Attack Surface The AI tooling ecosystem continues to accumulate critical debt. CVE-2025-71338 is a CVSS 10.0 path traversal in Flowise that allows unauthenticated attackers to write arbitrary…

    Post summary

    The post discloses a new CVE-2025-71338, a critical path‑traversal flaw in Flowise that permits unauthenticated users to write arbitrary data, but it offers no evidence of exploitation, a PoC, or a patch.

    1000035
    84 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-71338 — CVSS 10/10 ██████████ Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vQ3E5MMHhV

    Post summary

    The tweet alerts users to a critical path‑traversion flaw in Flowise (CVE‑2025‑71338) with CVSS 10/10, emphasizes the availability of a patch, and urges immediate action.

    10000133
    60 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🔐 🚨 CRITICAL: CVE-2025-71338 — Flowise CVSS 10.0 RCE Unauthenticated path traversal → arbitrary file write → package.json overwrite → full RCE. Affects Flowise ≤ 2.2.7. Patch to 3.1.3 NOW. 🔗 https://threataft.com/articles/cve-2025-71338-flowise-arbitrary-file-write-rce #CyberSecurity #ThreatIntel #infosec #Flowise #AI

    Post summary

    The snippet announces the CVE-2025-71338 vulnerability in Flowise, provides technical details of the RCE, and urges applying the available 3.1.3 patch immediately.

    0000061
    31 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🌊 Flowise users: CVE-2025-71338 is a CVSS 10 path traversal letting unauthenticated attackers write arbitrary files and chain to full RCE via the document-store API. No auth needed. Patch now. #AppSec #CyberSecurity https://secalerts.co/vulnerability/CVE-2025-71338?utm_campaign=x https://t.co/4KpfLheBOj

    Post summary

    The tweet announces CVE‑2025‑71338 as a high‑severity path traversal that enables unauthenticated RCE, and urges users to apply the available patch.

    0000064
    845 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more