CVE-2025-71333 - Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
CVE ID :CVE-2025-71333 Published : June 25, 2026, 9:41 p.m. | 1 hour, 30 minutes ago Description :Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in...