CVE-2025-11898: Flowring Technology|Agentflow - Arbitrary File Reading through Path Traversal
Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11898?
CVE-2025-11898 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive system files.
How do I fix CVE-2025-11898?
To fix CVE-2025-11898, ensure that all instances of Flowring Agentflow are updated to the latest patched version that addresses the arbitrary file reading vulnerability.
What types of systems are affected by CVE-2025-11898?
CVE-2025-11898 affects the Flowring Agentflow software by allowing unauthenticated remote attackers to exploit its file reading capabilities.
What is the impact of CVE-2025-11898?
The impact of CVE-2025-11898 includes the potential for attackers to access and download arbitrary files from the system, leading to data breaches.
How can I mitigate the risks associated with CVE-2025-11898?
To mitigate risks associated with CVE-2025-11898, restrict access to the affected application and monitor system logs for suspicious activities.