Description
The WriteFileTool in Flowise does not restrict the file path for reading, allowing authenticated attackers to exploit this vulnerability to write arbitrary files to any path in the file system, potentially leading to remote command execution.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.8
- Patched version(s): 3.0.8
References
Could your website be exposed too?
SmartScanner can check your website for Flowise is vulnerable to arbitrary file write through its WriteFileTool and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise is vulnerable to arbitrary file exposure through its ReadFileTool - Vulnerability
- @appium/support has a Zip Slip arbitrary file write in its ZIP extraction - CVE-2026-30973
- Flowise Vulnerable to SQL Injection via `tableName` Parameter - CVE-2025-29189
- DiracX-Web is vulnerable to attack through an Open Redirect on its login page - CVE-2025-54066


