CVE advisoryCRITICAL
CVE-2025-61913
Flowise Arbitrary File Read Write Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An issue exists in Flowise, a tool for building large language model flows, where unrestricted file path access allows authenticated attackers to read and write arbitrary files on the file system. This could potentially lead to remote command execution. Confirmation of Flowise usage and assessment of potential exposure