Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-71338

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 65.6%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2025-71338


Contact Us

Shodan ® - All rights reserved