CVE-2025-26319: Malicious File Upload
Published Mar 4, 2025
·Updated
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
Affected Software
3 affected components
FlowiseAI Flowise
npm/flowise<=2.2.6
FlowiseAI Flowise=2.2.6
Remediation
Patch Available
Event History
Mar 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyAffected Software
Mar 5, 2025
Advisory Published
via GitHub·12:30 AM
Apr 7, 2026
News Published
via BleepingComputer·05:02 PM
News Published
via BleepingComputer·05:03 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-26319?
CVE-2025-26319 is classified as a high severity vulnerability due to its potential for arbitrary file uploads.
2
How do I fix CVE-2025-26319?
To fix CVE-2025-26319, upgrade FlowiseAI Flowise to version 2.2.7 or later where the vulnerability is addressed.
3
What systems are affected by CVE-2025-26319?
CVE-2025-26319 affects FlowiseAI Flowise versions up to and including 2.2.6.
4
What are the impacts of CVE-2025-26319?
The impact of CVE-2025-26319 includes potential unauthorized access and execution of malicious files.
5
Is CVE-2025-26319 being actively exploited?
As of now, there have been no confirmed cases of active exploitation of CVE-2025-26319.