THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-71338 (CRITICAL 10.0) — Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application fil

[NVD] CVE-2025-71338 (CRITICAL 10.0) — Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application fil

lownvdPublished 2026-06-25

CVE-2025-71338 CVSS: 10.0 CRITICAL Published: 2026-06-25T22:16:59.520

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71338