CVE-2026-12821: FlowiseAI Flowise S3 Document Loader S3.ts path traversal
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12821?
The severity of CVE-2026-12821 is classified as medium with a CVSS score of 6.3.
How do I fix CVE-2026-12821?
To fix CVE-2026-12821, update FlowiseAI Flowise to the latest version available that addresses this vulnerability.
What can be exploited in CVE-2026-12821?
CVE-2026-12821 can be exploited to perform a path traversal attack through the S3 Document Loader component.
What versions of FlowiseAI Flowise are affected by CVE-2026-12821?
FlowiseAI Flowise versions up to 3.1.2 are affected by CVE-2026-12821.
What is the impact of CVE-2026-12821?
The impact of CVE-2026-12821 includes possible unauthorized access to the file system due to path traversal.