Impact
The S3 Document Loader contains a path traversal vulnerability in S3.ts, allowing an attacker to supply malicious path components that cause the loader to resolve to directories outside of the intended S3 bucket path. This flaw can lead to reading or executing files on the host system, compromising confidentiality and integrity. The flaw is a classic path traversal weakness identified as CWE-22.
Affected Systems
The affected product is FlowiseAI's Flowise application up to version 3.1.2, as identified by the vendor naming FlowiseAI:Flowise. The vulnerability resides in the documentloaders/S3/S3.ts component. No specific versions beyond 3.1.2 are listed; newer releases are presumed patched. The CPE enumerates flowiseai:flowise.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate risk. EPSS is not available, so exploitation probability is uncertain; the vulnerability can be leveraged remotely through crafted S3 loader requests. It is not listed in the CISA KEV catalog, implying no publicly known exploit, but the remote nature and lack of a mitigation response from the vendor increase the potential impact. Attackers could remotely execute the Object Key manipulation if the component is exposed over the network, enabling traversal into server files.
OpenCVE Enrichment