CVE-2026-56273: Flowise - Path Traversal in Vector Store basePath Parameter
Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations, potentially enabling code execution or data exfiltration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flowiseto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56273?
The severity of CVE-2026-56273 is medium with a CVSS score of 4.9.
How do I fix CVE-2026-56273?
To fix CVE-2026-56273, update Flowise to version 3.1.0 or later, which addresses the path traversal vulnerability.
What is the impact of CVE-2026-56273?
CVE-2026-56273 allows authenticated attackers to write vector store data to arbitrary filesystem locations, potentially leading to unauthorized access.
What software is affected by CVE-2026-56273?
The affected software is Flowise, specifically versions prior to 3.1.0.
Who is at risk from CVE-2026-56273?
Authenticated users with valid API tokens are at risk from CVE-2026-56273 as they can exploit the path traversal vulnerability.