Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-61913

Опубликовано: 08 окт. 2025
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading to remote command execution. Flowise 3.0.8 fixes this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Версия до 3.0.8 (исключая)

EPSS

Процентиль: 75%
0.009
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.9
github
4 месяца назад

Flowise is vulnerable to arbitrary file write through its WriteFileTool

EPSS

Процентиль: 75%
0.009
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-22