---
id: CVE-2025-71334
title: >-
  Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an
  arbitrary file access vulnerability due to missing validation that the
  chatflowId and chatId parameters are UUIDs or numbers in file handling
  operations
summary: >-
  Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an
  arbitrary file access vulnerability due to missing validation that the
  chatflowId and chatId parameters are UUIDs or numbers in file handling
  operations. By supplying…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: flowiseai
product: flowise
affected:
  - flowise < 3.0.6
patched:
  - flowise 3.0.6
published: '2026-06-25'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71334'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/commit/8bd3de41533de78e4ef6c980e5704a1f9cb7ae6f
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/commit/c2b830f279e454e8b758da441016b2234f220ac7
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-q67q-549q-p849
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-arbitrary-file-access-via-missing-chat-flow-id-validation
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-q67q-549q-p849
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.0436
epssPercentile: 0.90929
exploits:
  nuclei:
    - CVE-2025-71334
  checkedAt: '2026-09-30T17:13:56.203Z'
exploitAvailable: true
ingestedAt: '2026-09-30T17:13:20.776Z'
---

## Overview

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints (via streamStorageFile) to read arbitrary files. Arbitrary file write may lead to remote code execution.

## Affected

- `flowise < 3.0.6`

## Remediation

Upgrade past the affected range:

- `flowise 3.0.6`
