{"id":"CVE-2025-26319","title":"FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.","summary":"FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"flowiseai","product":"flowise","affected":["flowise = 2.2.6"],"published":"2025-03-04","updated":"2026-09-30","sourceUpdated":"2026-09-30T17:10:00.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-26319","references":[{"url":"https://github.com/dorattias/CVE-2025-26319","label":"cve@mitre.org"},{"url":"https://github.com/dorattias/CVE-2025-26319","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.55869,"epssPercentile":0.99015,"exploits":{"github":2,"githubRepos":["https://github.com/dorattias/CVE-2025-26319","https://github.com/redpack-kr/CVE-2025-26319"],"nuclei":["CVE-2025-26319"],"checkedAt":"2026-09-30T17:13:56.180Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T17:13:20.705Z","slug":"CVE-2025-26319","body":"## Overview\n\nFlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.\n\n## Affected\n\n- `flowise = 2.2.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":77,"depthScoreParts":{"impact":53.9,"likelihood":11.2,"exploitation":12,"ransomware":0},"changes":[]}