peter bassill · operator
$ cve CVE-2025-61913 JSON

CVE-2025-61913

9.9
CRITICAL · CVSS 3.1 · EPSS 13% (pctl 96)

Patch early

EPSS 13% — above the 10% action threshold.

Description

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading to remote command execution. Flowise 3.0.8 fixes this vulnerability.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS12.95% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2025-10-08
Last modified2026-09-30

Affected (1)

VendorProduct
flowiseaiflowise

References

→ the Explorer  ·  watch your stack  ·  NVD