External risk intelligence

Flowise Arbitrary File Read Write Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2025-61913

Flowise is a web-based user interface for building LLM flows. Applications of this type are commonly deployed as web services, often accessible via the network to allow collaborative workflow management or integration with external endpoints, making it likely to be reachable from an internet-facing or corporate network edge.

Path Traversal

Flowiseai Flowise

before 3.0.8

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Flowise, a tool used for building large language model flows. The issue involves unrestricted file path access, which could allow authenticated attackers to read or write files anywhere on the system, potentially leading to remote command execution. The main concern is confirming if this technology is in use and assessing the scope of potential exposure.

  • Allows reading/writing any file on the system.
  • Critical access controls for LLM flow builders.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could leverage an authenticated session to trick the Flowise application into reading or writing files anywhere on the server's file system, potentially leading to unauthorized command execution. This is possible because the file path handling in the WriteFileTool and ReadFileTool components does not adequately restrict access.

  • Authenticated access required.
  • Unrestricted file path access.
  • Arbitrary file read/write, potential RCE.

Live Threat

Current exploitation, exposure, and threat context

Authenticated users could read and write arbitrary files on the system where Flowise is deployed, potentially leading to the execution of commands when the vulnerability is supported by the advisory.

  • Arbitrary file read/write.
  • Unauthorized file access.
  • Possible command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability in Flowise, as it impacts a user interface for building LLM flows that can be deployed as a web service. The first practical step is to identify all Flowise instances, determine their network reachability and business criticality, and then confirm the accountable owner before planning remediation.

  • Application owners must own this issue.
  • Verify Flowise instance reachability and criticality.
  • Plan remediation based on verified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a visual, drag-and-drop platform designed to help users construct customized workflows for large language models. It acts as an interface that simplifies how data flows between different AI components and external tools, often serving as a web-based service for teams to manage and integrate their LLM applications.

What is the weakness in CVE-2025-61913?

This vulnerability is classified as Improper Limitation of a Pathname to a Restricted Directory, or CWE-22. It occurs because the ReadFileTool and WriteFileTool components fail to properly sanitize or restrict user-supplied file paths. This allows the application to be tricked into accessing files outside of its intended scope, granting unauthorized read and write capabilities across the entire file system.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by interacting with the file tools while authenticated. The vulnerability requires a valid user session to issue requests that manipulate file paths. Note that simply having the software installed is not enough; the attacker must be able to reach and interact with these specific tool components through the application interface to exploit the lack of path validation.

Is my Flowise instance at risk?

Halo Surface Signal indicates that Flowise instances are commonly deployed as web services accessible over a network. If your instance is reachable from the internet or a wide corporate network, it is at higher risk because the interface is exposed to authenticated users who could potentially leverage this flaw. You should consider its network accessibility and who has permission to log in.

How do I secure my environment against CVE-2025-61913?

The primary response is to update your Flowise software to version 3.0.8 or later, where this path restriction issue is resolved. Begin by identifying all deployed instances, confirming who owns each service, and prioritizing updates for those that are network-accessible. Once confirmed, coordinate the upgrade to ensure the file path validation logic is correctly implemented.

References