HIGH
Flowise: File Upload Validation Bypass in createAttachment
Published Apr 23, 2026
8.8
HIGHCVSS 3.1
EPSS 0.69%
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally allow JavaScript uploads. This enables attackers to persistently store malicious Node.js web shells on the server, potentially leading to Remote Code Execution (RCE). This vulnerability is fixed in 3.1.0.
Affected products
-
- Version < 3.1.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
flowise
npm
Introduced 0 Fixed 3.1.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | flowise | 0 | 3.1.0 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-rh7v-6w34-w2rr exploitx_refsource_CONFIRMVendor Advisory
- https://github.com/advisories/GHSA-rh7v-6w34-w2rr Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41269
| Link | Providers | Tags |
|---|---|---|
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-rh7v-6w34-w2rr | exploitx_refsource_CONFIRMVendor Advisory | |
| https://github.com/advisories/GHSA-rh7v-6w34-w2rr | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41269 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 18, 2026
Link CVE-2026-41269
CISA Vulnrichment
GHSA-RH7V-6W34-W2RR Updated Apr 24, 2026