External risk intelligence

Flowise Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-26319

Flowise is a low-code platform often deployed as a web application to provide interfaces for LLM workflows and automation. These platforms are commonly hosted as internet-facing web services or APIs to allow external connectivity and integration with other web-based services, making the application interface and its API endpoints, such as the attachment handler, frequently exposed to the internet.

Unrestricted File Upload

Flowiseai Flowise

2.2.6

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability identified in Flowise, a low-code platform used for building AI workflows. The vulnerability, an arbitrary file upload issue, could allow unauthorized access and manipulation of files within the system, potentially impacting the integrity and availability of services if exploited. The main concern is confirming relevance and exposure to your environment.

  • Allows uploading unauthorized files.
  • Critical flaw in a popular AI workflow tool.
  • Assess your use of Flowise and its exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by uploading a file to the application's attachment API. This requires no prior authentication or special user interaction, allowing an attacker to directly upload a malicious file. Successfully triggering the vulnerability could allow an attacker to gain control over the affected system by uploading arbitrary files.

  • No authentication or user interaction needed.
  • Uploading a file to the attachment API.
  • Arbitrary file upload leading to system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload arbitrary files to the server when the affected endpoint is accessed. The specific impact would depend on the type of file uploaded and the server's configuration.

  • Arbitrary file upload risk.
  • Via vulnerable API endpoint.
  • Potential server compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in FlowiseAI Flowise affects the file upload API, potentially impacting teams responsible for application development, infrastructure, or security operations. The immediate priority is to identify all instances of Flowise, assess their exposure and criticality, and confirm ownership for remediation planning.

  • Application and Platform owners should lead.
  • Verify external reachability and business impact.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise and what is it used for?

Flowise is a low-code software platform designed to help users build and manage LLM-powered AI workflows. It provides a visual interface for creating automation pipelines and is often hosted as a web application or API service to facilitate connectivity and integration with other digital systems.

What does CVE-2025-26319 mean?

This CVE describes an arbitrary file upload vulnerability, classified as CWE-434. In plain terms, the software fails to properly restrict the types of files that can be uploaded to its attachment API. This weakness allows an attacker to send unauthorized files to the server, which could potentially lead to full system compromise depending on how the server handles and executes those files.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by interacting directly with the specific /api/v1/attachments endpoint. The process does not require any login credentials, special user permissions, or human interaction. Simply sending a malicious file to this endpoint is sufficient to initiate the upload process; standard system usage that does not involve this specific attachment API path does not trigger the vulnerability.

Is my Flowise instance at risk?

Halo Surface Signal indicates that Flowise is frequently deployed as an internet-facing service to support external AI integrations. If your instance is accessible from the public internet, it faces a higher likelihood of being reachable by unauthorized parties. Instances strictly restricted to internal networks have a smaller attack surface, but you should still verify your deployment's visibility.

How should I respond to this threat?

Begin by identifying all running instances of Flowise within your environment. Coordinate with your application and platform owners to assess the criticality and network reachability of each instance. Once mapped, prioritize those that are internet-facing for remediation, and continue monitoring for updates or patches from the vendor to resolve the underlying API flaw.

References