CVE-2025-71338 - Flowise - Arbitrary File Write to Remote Code Execution via document-store API
CVE ID :CVE-2025-71338 Published : June 25, 2026, 9:41 p.m. | 1 hour, 30 minutes ago Description :Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers...