Vulnerabilities/

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

Severity:
High

Description

Flowise on current main allows an authenticated user with documentStores:preview-process permission to trigger the S3 Directory
document loader with attacker-controlled S3 object keys.

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-components
Anything's wrong? Let us know Last updated on August 04, 2026