Vulnerability Intelligence Report
Flowise is vulnerable to arbitrary file read, arbitrary file write
CVE-2025-61913
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading to remote command execution. Flowise 3.0.8 fixes this vulnerability.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:11.85%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| FlowiseAI | Flowise | < 3.0.8 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
11.853%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2025-10-03T22:21:59 |
| Published | 2025-10-08T22:43:24 |
| Last Updated | 2025-10-14T14:18:13 |
Community Chatter & Buzz