216.73.216.6

CVE-2025-61913

· Published 08/10/2025 23:15 · Modified 09/10/2025 15:50

Labels: CVE-2025-61913 2025-10-08CVE-2025-61913CWE-22[email protected]

Essential information

Published
08/10/2025 23:15
Modified
09/10/2025 15:50
Author
Creator
CVSS
9.9 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading to remote command execution. Flowise 3.0.8 fixes this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
flowise / flowise cpe:2.3:a:flowise:flowise:*:*:*:*:*:*:*:*

References