cvedb.io
CVE-2025-61687
HIGH · CVSS 8.3
EPSS exploitation probability: 0%
Published 2025-10-06T16:15:35.223 · Last modified 2026-06-17T09:50:46.747

Summary

Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI allows authenticated users to upload arbitrary files without proper validation. This enables attackers to persistently store malicious Node.js web shells on the server, potentially leading to Remote Code Execution (RCE). The system fails to validate file extensions, MIME types, or file content during uploads. As a result, malicious scripts such as Node.js-based web shells can be uploaded and stored persistently on the server. These shells expose HTTP endpoints capable of executing arbitrary commands if triggered. The uploaded shell does not automatically execute, but its presence allows future exploitation via administrator error or chained vuln

Affected products

flowiseai — flowise

Does this affect you?

Add your gear to cvedb and we'll alert you only when flowiseai ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.