Skip to content

Known CVE

Flowise - Path Traversal

Flowise < 3.0.6 contains a path traversal vulnerability caused by improper validation of the chatId parameter in /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints, letting unauthenticated attackers read arbitrary files including sensitive database files.

CVE-2025-71324

High2025CVSS 7.5CWE-73

cve2025 · flowise · lfi · path-traversal · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website