GHSA-67qj-p3v2-73g7LowCVSS 6.3
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-12821
- https://github.com/dxz0069/softwareoverflow/blob/main/flowise_s3_loader_object_key_path_traversal_vulndb.md
- https://vuldb.com/cve/CVE-2026-12821
- https://vuldb.com/submit/837578
- https://vuldb.com/vuln/372611
- https://vuldb.com/vuln/372611/cti
- https://github.com/advisories/GHSA-67qj-p3v2-73g7