Path traversal in Flowise - #VU140063
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to write arbitrary files.
The vulnerability exists due to path traversal in the S3 Directory document loader when processing attacker-controlled S3 object keys. A remote user can supply crafted S3 object keys containing traversal sequences to write arbitrary files.
Exploitation requires the `documentStores:preview-process` permission and can be performed by pointing the loader to an attacker-controlled S3-compatible endpoint via `serverUrl`.