Back to all
2026-09-29

Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type

ZUSOART ID
ZA-2026-12
CVE ID
CVE-2026-96431
Vulnerability Type
CWE-434: Unrestricted Upload of File with Dangerous Type
CVSS 4.0 Base
9.3
Description

Unrestricted  Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API  endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated  users to execute arbitrary system commands via a malicious file.

‍

Vendor
Flowring Technology Corp
Product
Category
Version affected
Agentflow 4.0
Before 2023/03/24
Mitigations

Update Agentflow 4.0 to 2023/03/24.

‍

Release date
2026-09-29
Credit

Jian You Chen (Jeremy Chen) of ZUSO ART

‍