CVE-2025-26319 is a critical arbitrary file upload vulnerability affecting FlowiseAI Flowise v2.2.6, specifically within the /api/v1/attachments endpoint. This flaw carries a CVSS score of 9.8, indicating a severe risk with network-based exploitation, low attack complexity, and high impact on confidentiality, integrity, and availability. While not yet in the KEV catalog, its high EPSS score and community discussion suggest a significant likelihood of future exploitation, with Nuclei templates already available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.6CPE matchmatch criteria | cpe:2.3:a:flowiseai:flowise:2.2.6:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.