CVE-2026-69252 | FlowiseAI Flowise up to 3.1.2 File Management /api/v1/files getAllFiles/deleteFile path permission
A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been rated as critical. Affected by this vulnerability is the function getAllFiles/deleteFile of the file /api/v1/files of the component File Management. The manipulation of the argument path leads to permission issues.
This vulnerability is uniquely identified as CVE-2026-69252. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More