THREAT OPS › Threat News › [NVD] CVE-2025-71338 (CRITICAL 10.0) — Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application fil
[NVD] CVE-2025-71338 (CRITICAL 10.0) — Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application fil
CVE-2025-71338 CVSS: 10.0 CRITICAL Published: 2026-06-25T22:16:59.520
Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.
Indicators of compromise
- CVE-2025-71338cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71338