Flutter is a cross-platform application development framework whose vulnerability footprint centers on file-handling and input-validation weaknesses affecting its core framework and associated plugin ecosystem, particularly in Android-facing components such as file_selector_android and image_picker_android. The recurring pattern of path-traversal and improper pathname-restriction flaws reflects the risk surface introduced when third-party plugins mediate access to device storage and user-supplied file paths. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flutter over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3095CRITICAL The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC | Oct 27, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-27704HIGH The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41 | Feb 25, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-54462HIGH The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a | Jan 29, 2025 | 7.1 | 20 | NO | NO |
CVE-2024-54461HIGH The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with | Jan 29, 2025 | 7.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flutter.
Media articles that mention a CVE ID that affects a product developed by Flutter — matched by CVE ID, not by vendor name.