Flowise is vulnerable to arbitrary file write through its WriteFileTool
- Severity:
- High
Description
The WriteFileTool in Flowise does not restrict the file path for reading, allowing authenticated attackers to exploit this vulnerability to write arbitrary files to any path in the file system, potentially leading to remote command execution.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.8
- Patched version(s): 3.0.8
References
Related Issues
- Flowise is vulnerable to arbitrary file exposure through its ReadFileTool - Vulnerability
- @appium/support has a Zip Slip arbitrary file write in its ZIP extraction - CVE-2026-30973
- Flowise Vulnerable to SQL Injection via `tableName` Parameter - CVE-2025-29189
- DiracX-Web is vulnerable to attack through an Open Redirect on its login page - CVE-2025-54066
You might also like:
- Tags:
- npm
- flowise-components
Anything's wrong? Let us know Last updated on November 15, 2025


