← Back to CVE List
Vulnerability Intelligence Report
Flowise is vulnerable to arbitrary file read, arbitrary file write

CVE-2025-61913

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading to remote command execution. Flowise 3.0.8 fixes this vulnerability.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:11.85%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
FlowiseAI Flowise < 3.0.8 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
11.853%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2025-10-03T22:21:59
Published2025-10-08T22:43:24
Last Updated2025-10-14T14:18:13

LINK COPIED TO CLIPBOARD